CVE-2020-27748
published 2021-06-01CVE-2020-27748: A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
1.44%
70.6th percentile
A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbird. An attacker could potentially send a victim a URI that automatically attaches a sensitive file to a new email. If a victim user does not notice that an attachment was added and sends the email, this could result in sensitive information disclosure. It has been confirmed that the code behind this issue is in xdg-email and not in Thunderbird.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xdg-utils | — | — |
| freedesktop | xdg-utils | — | — |
| freedesktop | xdg-utils | >= 1.1.0 | — |
| msrc | cbl2_xdg-utils_1.1.3-7_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbi
vendor_msrc·2021-06-08·CVSS 6.5
CVE-2020-27748 [MEDIUM] CWE-201 A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbi
A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbird. An attacker could potentially send a victim a URI that automatically attaches a sensitive file to a new email. If a victim user does not notice that an attachment was added and sends the email, this could result in sensitive information disclosure. It has been confirmed that the code behind this issue is in xdg-email and not in Thunderbird.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to k
Ubuntu
xdg-utils vulnerability
vendor_ubuntu·2020-11-26
CVE-2020-27748 xdg-utils vulnerability
Title: xdg-utils vulnerability
Summary: xdg-utils could be made to expose sensitive information.
Jens Mueller discovered that xdg-utils incorrectly handled certain URI.
An attacker could possibly use this issue to expose sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
xdg-utils: local file inclusion vulnerability
vendor_redhat·2020-02-05·CVSS 6.5
CVE-2020-27748 [MEDIUM] CWE-201 xdg-utils: local file inclusion vulnerability
xdg-utils: local file inclusion vulnerability
A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbird. An attacker could potentially send a victim a URI that automatically attaches a sensitive file to a new email. If a victim user does not notice that an attachment was added and sends the email, this could result in sensitive information disclosure. It has been confirmed that the code behind this issue is in xdg-email and not in Thunderbird.
A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbird. A
Debian
CVE-2020-27748: xdg-utils - A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. Wh...
vendor_debian·2020·CVSS 6.5
CVE-2020-27748 [MEDIUM] CVE-2020-27748: xdg-utils - A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. Wh...
A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbird. An attacker could potentially send a victim a URI that automatically attaches a sensitive file to a new email. If a victim user does not notice that an attachment was added and sends the email, this could result in sensitive information disclosure. It has been confirmed that the code behind this issue is in xdg-email and not in Thunderbird.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-3c8x-jg6w-85xx: A flaw was found in the xdg-email component of xdg-utils-1
ghsa_unreviewed·2022-05-24
CVE-2020-27748 [MEDIUM] CWE-201 GHSA-3c8x-jg6w-85xx: A flaw was found in the xdg-email component of xdg-utils-1
A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbird. An attacker could potentially send a victim a URI that automatically attaches a sensitive file to a new email. If a victim user does not notice that an attachment was added and sends the email, this could result in sensitive information disclosure. It has been confirmed that the code behind this issue is in xdg-email and not in Thunderbird.
OSV
CVE-2020-27748: A flaw was found in the xdg-email component of xdg-utils-1
osv·2021-06-01·CVSS 6.5
CVE-2020-27748 [MEDIUM] CVE-2020-27748: A flaw was found in the xdg-email component of xdg-utils-1
A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderbird. An attacker could potentially send a victim a URI that automatically attaches a sensitive file to a new email. If a victim user does not notice that an attachment was added and sends the email, this could result in sensitive information disclosure. It has been confirmed that the code behind this issue is in xdg-email and not in Thunderbird.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-06-01
Published