CVE-2020-11879: Medium severity evolution vulnerability
An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make Evolution attach local files or directories to a composed email message without showing a warning to the user, as demonstrated by an attach=. value.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue in GNOME Evolution?
The vulnerability ID for this issue in GNOME Evolution is CVE-2020-11879.
What is the severity of CVE-2020-11879?
The severity of CVE-2020-11879 is medium with a severity value of 6.5.
What is the affected version of GNOME Evolution?
The affected version of GNOME Evolution is any version up to and excluding 3.35.91.
How can a website exploit CVE-2020-11879?
A website can exploit CVE-2020-11879 by using the proprietary 'mailto?attach=...' parameter to make Evolution attach local files or directories to a composed email message without showing a warning to the user.
Is there any fix or patch available for CVE-2020-11879?
Yes, the fix for CVE-2020-11879 is available in GNOME Evolution version 3.35.91 and later.