Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-2604

Опубликовано: 17 июн. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.6

Описание

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.

РелизСтатусПримечание
devel

not-affected

3.56.2-8
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

released

3.28.5-0ubuntu0.18.04.3+esm1
esm-infra/focal

released

3.36.5-0ubuntu1+esm1
esm-infra/xenial

ignored

end of ESM support, was needed
jammy

released

3.44.4-0ubuntu1.2
noble

released

3.52.3-0ubuntu1.2
questing

released

3.56.2-3ubuntu0.1
resolute

not-affected

3.56.2-8
upstream

released

3.59.3

Показывать по

EPSS

Процентиль: 9%
0.00189
Низкий

5.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.6
redhat
6 месяцев назад

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.

CVSS3: 5.6
nvd
около 2 месяцев назад

A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.

CVSS3: 5.6
debian
около 2 месяцев назад

A flaw was found in evolution-data-server. Inconsistent comparison log ...

suse-cvrf
2 месяца назад

Security update for evolution-data-server

suse-cvrf
5 месяцев назад

Security update for evolution-data-server

EPSS

Процентиль: 9%
0.00189
Низкий

5.6 Medium

CVSS3