KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or encrypted, via HTML formatted email.
http://secunia.com/advisories/14925
http://mail.kde.org/pipermail/kmail-devel/2005-February/015490.html