Logo
vulnerabilityCVE-2020-27748
Name
CVE-2020-27748
Source
NVD ( link)Debian ( link)
Description
A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbird. An attacker could potentially send a victim a URI that automatically attaches a sensitive file to a new email. If a victim user does not notice that an attachment was added and sends the email, this could result in sensitive information disclosure. It has been confirmed that the code behind this issue is in xdg-email and not in Thunderbird.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
xdg-utils
Patched

Vulnerability Ratings#


6.5
CVSSv31
4.3
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
1.1.3
Patched
yocto
scarthgap
1.1.3
Patched

Resolved with patches#


xdg-utils (yocto:kirkstone)

#
Title
Author
Resolve
1
xdg-email: remove attachment handling from mailto
=?UTF-8?q?J=C3=B6rg=20Thalheim?= <joerg@thalheim.io>
CVE-2020-27748

xdg-utils (yocto:master)

#
Title
Author
Resolve
1
xdg-email: remove attachment handling from mailto
=?UTF-8?q?J=C3=B6rg=20Thalheim?= <joerg@thalheim.io>
CVE-2020-27748

xdg-utils (yocto:scarthgap)

#
Title
Author
Resolve
1
xdg-email: remove attachment handling from mailto
=?UTF-8?q?J=C3=B6rg=20Thalheim?= <joerg@thalheim.io>
CVE-2020-27748