Logo
vulnerabilityCVE-2022-4055
Name
CVE-2022-4055
Source
NVD ( link)Debian ( link)
Description
When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
xdg-utils
Patched

Vulnerability Ratings#


7.4
CVSSv31
7.4
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
1.1.3
Patched
yocto
scarthgap
1.1.3
Patched

Resolved with patches#


xdg-utils (yocto:kirkstone)

#
Title
Author
Resolve
1
Disable special support for Thunderbird in xdg-email (fixes
Gabriel Corona <gabriel.corona@enst-bretagne.fr>
CVE-2022-4055

xdg-utils (yocto:master)

#
Title
Author
Resolve
1
Patch #1
Richard Purdie <richard.purdie@linuxfoundation.org>
CVE-2022-4055

xdg-utils (yocto:scarthgap)

#
Title
Author
Resolve
1
Patch #1
Richard Purdie <richard.purdie@linuxfoundation.org>
CVE-2022-4055