REDHAT-BUG-1899769: Medium severity freedesktop.org xdg-utils vulnerability
A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbird. An attacker could potentially send a victim a URI that automatically attaches a sensitive file to a new email. If a victim user does not notice that an attachment was added and sends the email, this could result in sensitive information disclosure. It has been confirmed that the code behind this issue is in xdg-email and not in Thunderbird.
Reference: https://bugzilla.mozilla.org/showbug.cgi?id=1613425 Upstream commit: https://gitlab.freedesktop.org/Mic92/xdg-utils/-/commit/1f199813e0eb0246f63b54e9e154970e609575af
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1899769?
The severity of REDHAT-BUG-1899769 is considered to be high due to the potential for sensitive file attachments to be automatically included in emails.
How do I fix REDHAT-BUG-1899769?
To fix REDHAT-BUG-1899769, update the xdg-utils package to a version later than 1.1.0-rc1 that addresses the vulnerability.
What does REDHAT-BUG-1899769 affect?
REDHAT-BUG-1899769 affects the xdg-email component of xdg-utils version 1.1.0-rc1 and newer.
Can I be exploited through a mailto: URI as described in REDHAT-BUG-1899769?
Yes, if you receive a malicious mailto: URI, your email client could potentially process it in a way that automatically attaches sensitive files.
Who is responsible for fixing REDHAT-BUG-1899769?
The developers of xdg-utils are responsible for addressing the vulnerabilities detailed in REDHAT-BUG-1899769 through updates and patches.