Input validation error in Evolution - CVE-2020-11879

 

Input validation error in Evolution - CVE-2020-11879

Published: April 17, 2020 / Updated: August 8, 2020


Vulnerability identifier: #VU34442
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11879
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make Evolution attach local files or directories to a composed email message without showing a warning to the user, as demonstrated by an attach=. value.


Affected software

Evolution
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Workstation Extension 12
evolution-debuginfo
evolution-debugsource
evolution-devel
evolution
evolution-lang

How to mitigate CVE-2020-11879

Install update from vendor's website.

Evolution - update to 3.35.91
evolution-debuginfo - update to 3.22.6-19.14.1
evolution-debugsource - update to 3.22.6-19.14.1
evolution-devel - update to 3.22.6-19.14.1
evolution - update to 3.22.6-19.14.1
evolution-lang - update to 3.22.6-19.14.1

External References

Related Security Bulletins