REDHAT-BUG-733504: Low severity evolution vulnerability
This is another Evolution security issue that I found upstream but presume also affects Fedora and would like to put on the Fedora security team's radar. If my filing such bugs is not appreciated, please let me know and I will stop.
Description of problem: Evolution registers a "mailto:" URL handler that accepts a parameter to attach a local file. Thus, a web site can launch the composer on an email with a confidential file attached and try to trick the user into sending it.
Version-Release number of selected component (if applicable): Upstream gnome-3-0 branch as of 2011-08-24
How reproducible: Always
Steps to Reproduce: 1. Go to https://mattmccutchen.net/private/evolution-mailto-test . 2. Click "Send" in the composer.
Actual results: Your SSH private key is emailed to me.
Expected results: A prompt is shown and you decline to attach the private key.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-733504?
The severity of REDHAT-BUG-733504 is currently under investigation but it is considered a security issue affecting GNOME Evolution.
How do I fix REDHAT-BUG-733504?
To fix REDHAT-BUG-733504, you should update to the latest version of GNOME Evolution that includes security patches addressing this vulnerability.
Which versions of GNOME Evolution are affected by REDHAT-BUG-733504?
Versions of GNOME Evolution from 2011-08-24 and later are affected by REDHAT-BUG-733504.
What impact does REDHAT-BUG-733504 have on users?
REDHAT-BUG-733504 may allow unauthorized access or manipulation of 'mailto:' URLs, potentially compromising user privacy and security.
Who should I contact regarding REDHAT-BUG-733504?
If you have further questions or concerns about REDHAT-BUG-733504, you should contact the Fedora security team or the GNOME project maintainers.