Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:7672

Опубликовано: 04 окт. 2025
Источник: rocky
Оценка: Moderate

Описание

Moderate: xdg-utils security update

The xdg-utils package is a set of simple scripts that provide basic desktop integration functions for any Free Desktop.

Security Fix(es):

  • xdg-utils: improper parse of mailto URIs allows bypass of Thunderbird security mechanism for attachments (CVE-2022-4055)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
xdg-utilsnoarch13.el9_6xdg-utils-1.1.3-13.el9_6.noarch.rpm
xdg-utilsnoarch13.el9_6xdg-utils-1.1.3-13.el9_6.noarch.rpm
xdg-utilsnoarch13.el9_6xdg-utils-1.1.3-13.el9_6.noarch.rpm
xdg-utilsnoarch13.el9_6xdg-utils-1.1.3-13.el9_6.noarch.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.4
ubuntu
около 3 лет назад

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
redhat
больше 3 лет назад

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
nvd
около 3 лет назад

When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

CVSS3: 7.4
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 7.4
debian
около 3 лет назад

When xdg-mail is configured to use thunderbird for mailto URLs, improp ...