First published: Thu Aug 25 2011(Updated: )
This is another Evolution security issue that I found upstream but presume also affects Fedora and would like to put on the Fedora security team's radar. If my filing such bugs is not appreciated, please let me know and I will stop. Description of problem: Evolution registers a "mailto:" URL handler that accepts a parameter to attach a local file. Thus, a web site can launch the composer on an email with a confidential file attached and try to trick the user into sending it. Version-Release number of selected component (if applicable): Upstream gnome-3-0 branch as of 2011-08-24 How reproducible: Always Steps to Reproduce: 1. Go to <a href="https://mattmccutchen.net/private/evolution-mailto-test">https://mattmccutchen.net/private/evolution-mailto-test</a> . 2. Click "Send" in the composer. Actual results: Your SSH private key is emailed to me. Expected results: A prompt is shown and you decline to attach the private key.
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME Evolution | >=2011-08-24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-733504 is currently under investigation but it is considered a security issue affecting GNOME Evolution.
To fix REDHAT-BUG-733504, you should update to the latest version of GNOME Evolution that includes security patches addressing this vulnerability.
Versions of GNOME Evolution from 2011-08-24 and later are affected by REDHAT-BUG-733504.
REDHAT-BUG-733504 may allow unauthorized access or manipulation of 'mailto:' URLs, potentially compromising user privacy and security.
If you have further questions or concerns about REDHAT-BUG-733504, you should contact the Fedora security team or the GNOME project maintainers.