Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-11879

Опубликовано: 17 апр. 2020
Источник: redhat
CVSS3: 6.5

Описание

An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make Evolution attach local files or directories to a composed email message without showing a warning to the user, as demonstrated by an attach=. value.

Меры по смягчению последствий

Either:

  1. Do not use mailto links at all
  2. Always double-check in the user interface that there are no unwanted attachments before sending emails; especially when the email originates from clicking a mailto link.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6evolutionOut of support scope
Red Hat Enterprise Linux 7evolutionAffected
Red Hat Enterprise Linux 8evolutionWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=1867605evolution: attaching local filed/directories to composed email can lead to unintended information disclosure

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 6 лет назад

An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make Evolution attach local files or directories to a composed email message without showing a warning to the user, as demonstrated by an attach=. value.

CVSS3: 6.5
nvd
почти 6 лет назад

An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make Evolution attach local files or directories to a composed email message without showing a warning to the user, as demonstrated by an attach=. value.

CVSS3: 6.5
debian
почти 6 лет назад

An issue was discovered in GNOME Evolution before 3.35.91. By using th ...

suse-cvrf
больше 2 лет назад

Security update for evolution

CVSS3: 6.5
github
больше 3 лет назад

An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make Evolution attach local files or directories to a composed email message without showing a warning to the user, as demonstrated by an attach=.bash_history value.

6.5 Medium

CVSS3