Описание
A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 3.56.2-8 |
| esm-infra-legacy/xenial | not-affected | code not present |
| esm-infra/bionic | released | 3.28.5-0ubuntu0.18.04.3+esm1 |
| esm-infra/focal | released | 3.36.5-0ubuntu1+esm1 |
| esm-infra/xenial | ignored | end of ESM support, was needed |
| jammy | released | 3.44.4-0ubuntu1.2 |
| noble | released | 3.52.3-0ubuntu1.2 |
| questing | released | 3.56.2-3ubuntu0.1 |
| resolute | not-affected | 3.56.2-8 |
| upstream | released | 3.59.3 |
Показывать по
EPSS
5.6 Medium
CVSS3
Связанные уязвимости
A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.
A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.
A flaw was found in evolution-data-server. Inconsistent comparison log ...
EPSS
5.6 Medium
CVSS3