Candidate: CVE-2020-11879 PublicDate: 2020-04-17 18:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11879 https://gitlab.gnome.org/GNOME/evolution/issues/784 https://gitlab.gnome.org/GNOME/evolution/-/commit/6489f20d6905cc797e2b2581c415e558c457caa7 https://gitlab.gnome.org/GNOME/evolution/-/blob/master/NEWS Description: An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make Evolution attach local files or directories to a composed email message without showing a warning to the user, as demonstrated by an attach=. value. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N [6.5 MEDIUM] Patches_evolution: upstream_evolution: released (3.36.0-1) precise/esm_evolution: DNE trusty_evolution: ignored (out of standard support) trusty/esm_evolution: DNE xenial_evolution: ignored (end of standard support, was needed) bionic_evolution: needed eoan_evolution: ignored (reached end-of-life) focal_evolution: needed groovy_evolution: ignored (reached end-of-life) hirsute_evolution: ignored (reached end-of-life) impish_evolution: needed jammy_evolution: needed devel_evolution: needed