Release date:
2026-09-16 13:54:28 UTC
Description:
* SECURITY UPDATE: a mailto: URI could silently attach a local file when
Thunderbird was the configured handler
- debian/patches/CVE-2022-4055.patch: remove the Thunderbird special case
(run_thunderbird() and its callers) from scripts/xdg-email.in, so
mailto: URIs go to the desktop handler and no URI field is parsed;
the --attach option is dropped with it
- debian/patches/tests-xdg-email-thunderbird-passthrough.patch: rewrite the
autotest case that asserted the removed Thunderbird path so it asserts
the fixed behaviour instead
- CVE-2022-4055: unquoted subject= and body= in run_thunderbird() let a
mailto: URI append a -compose attachment= argument
- CVE-2020-27748: the attach= field of a mailto: URI was passed straight
through to -compose attachment=
Updated packages:
-
xdg-utils_1.1.3-4.1+tuxcare.els1_all.deb
sha:cd97cff3b1983d5a574189d1ebfed41ae2e5837d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.