Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-7672

Опубликовано: 22 мая 2025
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2025-7672: xdg-utils security update (MODERATE)

[1.1.3-13]

  • Update documentation for CVE-2022-4055 (RHEL-87487)

[1.1.3-12]

  • Fix CVE-2022-4055 (RHEL-87487)

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

xdg-utils

1.1.3-13.el9_6

Oracle Linux x86_64

xdg-utils

1.1.3-13.el9_6

Связанные CVE

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 2 лет назад

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
redhat
почти 3 года назад

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
nvd
больше 2 лет назад

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
msrc
4 месяца назад

Описание отсутствует

CVSS3: 7.4
debian
больше 2 лет назад

When xdg-mail is configured to use thunderbird for mailto URLs, improp ...