Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-13324

Источник: debian

Описание

Описание отсутствует

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gearyunfixedpackage
gearyno-dsatrixiepackage
gearypostponedbookwormpackage
gearypostponedbullseyepackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2492860

  • https://gitlab.gnome.org/GNOME/geary/-/work_items/1704

Связанные уязвимости

ubuntu
около 2 месяцев назад

[Unknown description]

CVSS3: 6.5
redhat
около 2 месяцев назад

A vulnerability has been identified in the **GNOME Geary** package within its **`mailto` URI handling** component. This flaw occurs because the email client automatically processes a non-standard `attach` parameter in email links without prompting or alerting the user. An attacker could exploit this by tricking a user into clicking a specially crafted link (for example, `mailto:user@example.com?attach=/path/to/sensitive_file`). When clicked, Geary will automatically open a new compose window with the specified local file already attached. Because there is no dialog box or visual warning indicating that the file was attached by the link rather than the user, the user might unknowingly send sensitive files or data to the attacker upon hitting send.