KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or encrypted, via HTML formatted email.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-0405
http://www.securiteam.com/unixfocus/5GP0B0AFFE.html
http://secunia.com/advisories/14925
http://mail.kde.org/pipermail/kmail-devel/2005-February/015490.html