xdg-utils-1.1.3-13.el9_6
エラータID: AXSA:2025-10482:01
The xdg-utils package is a set of simple scripts that provide basic desktop integration functions for any Free Desktop.
Security Fix(es):
* xdg-utils: improper parse of mailto URIs allows bypass of Thunderbird security mechanism for attachments (CVE-2022-4055)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2022-4055
When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.
Update packages.
When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.
N/A
SRPMS
- xdg-utils-1.1.3-13.el9_6.src.rpm
MD5: 91af226aaf53fdedf515d04e9db5ffeb
SHA-256: a25cd155745b74e96ae0c680130a1c44e7d9d83f6880b6de491aa628ed553f9b
Size: 314.06 kB
Asianux Server 9 for x86_64
- xdg-utils-1.1.3-13.el9_6.noarch.rpm
MD5: a3080fa82531b6fd868728b421008810
SHA-256: f451c2dbf8811de5f73cd26ad5d4ed0c68ee597a2dd7ed14a5d7c698db9ee4f8
Size: 76.29 kB