REDHAT-BUG-1899769: Medium severity freedesktop.org xdg-utils vulnerability

Published Nov 20, 2020
·
Updated

A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbird. An attacker could potentially send a victim a URI that automatically attaches a sensitive file to a new email. If a victim user does not notice that an attachment was added and sends the email, this could result in sensitive information disclosure. It has been confirmed that the code behind this issue is in xdg-email and not in Thunderbird.

Reference: https://bugzilla.mozilla.org/showbug.cgi?id=1613425 Upstream commit: https://gitlab.freedesktop.org/Mic92/xdg-utils/-/commit/1f199813e0eb0246f63b54e9e154970e609575af

Affected Software

1 affected component
freedesktop.org xdg-utils>=1.1.0-rc1

Event History

Nov 20, 2020
Data Sourced
via Red Hat·12:06 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-1899769?

The severity of REDHAT-BUG-1899769 is considered to be high due to the potential for sensitive file attachments to be automatically included in emails.

2

How do I fix REDHAT-BUG-1899769?

To fix REDHAT-BUG-1899769, update the xdg-utils package to a version later than 1.1.0-rc1 that addresses the vulnerability.

3

What does REDHAT-BUG-1899769 affect?

REDHAT-BUG-1899769 affects the xdg-email component of xdg-utils version 1.1.0-rc1 and newer.

4

Can I be exploited through a mailto: URI as described in REDHAT-BUG-1899769?

Yes, if you receive a malicious mailto: URI, your email client could potentially process it in a way that automatically attaches sensitive files.

5

Who is responsible for fixing REDHAT-BUG-1899769?

The developers of xdg-utils are responsible for addressing the vulnerabilities detailed in REDHAT-BUG-1899769 through updates and patches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203