Bug 13344

Summary: [CVE 21] xdg-utils 1.1.3 CVEs found
Product: [ROSA-based products] ROSA Fresh Reporter: Yury <y.tumanov>
Component: System (kernel, glibc, systemd, bash, PAM...)Assignee: ROSA Linux Bugs <bugs>
Status: RESOLVED WONTFIX QA Contact: ROSA Linux Bugs <bugs>
Severity: normal    
Priority: Normal CC: m.novosyolov, s.matveev, y.tumanov
Version: AllFlags: y.tumanov: secteam_verified+
Target Milestone: ---   
Hardware: All   
OS: Linux   
URL: CVE-2020-27748,
Whiteboard:
Platform: 2021.1 ROSA Vulnerability identifier:
RPM Package: ISO-related:
Bad POT generating: Upstream:

Description Yury 2023-05-03 18:22:01 MSK
Please patch CVEs for package xdg-utils version 1.1.3
  
INFO (CVEs are): xdg-utils 1.1.3
 cves found
CVE-2020-27748
Desc: A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbird. An attacker could potentially send a victim a URI that automatically attaches a sensitive file to a new email. If a victim user does not notice that an attachment was added and sends the email, this could result in sensitive information disclosure. It has been confirmed that the code behind this issue is in xdg-email and not in Thunderbird.
Link: https://nvd.nist.gov/vuln/detail/CVE-2020-27748
Severity: MEDIUM
Comment 1 Mikhail Novosyolov 2023-05-15 15:44:23 MSK
Мы это где-то обсуждали уже и решили не трогать.
Comment 2 Yury 2023-07-25 12:56:04 MSK
Secteam Verified