PT-2020-12913 · Gnome+2 · Gnome Evolution+2

Published

2020-03-15

·

Updated

2023-08-22

·

CVE-2020-11879

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GNOME Evolution versions prior to 3.35.91
Description An issue was discovered where a website or other source of mailto links can make Evolution attach local files or directories to a composed email message without showing a warning to the user. This is achieved by using the proprietary "mailto?attach=..." parameter, as demonstrated by an attach=. value.
Recommendations For versions prior to 3.35.91, update to version 3.35.91 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the "mailto?attach=..." parameter in mailto links until the issue is resolved.

Fix

Related Identifiers

ALT-PU-2020-1483
CVE-2020-11879
SUSE-SU-2023:3375-1
SUSE-SU-2023_3375-1

Affected Products

Alt Linux
Gnome Evolution
Suse