Input validation error in Evolution - CVE-2020-11879
Published: April 17, 2020 / Updated: August 8, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make Evolution attach local files or directories to a composed email message without showing a warning to the user, as demonstrated by an attach=. value.
Affected software
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Workstation Extension 12
evolution-debuginfo
evolution-debugsource
evolution-devel
evolution
evolution-lang
How to mitigate CVE-2020-11879
evolution-debuginfo - update to 3.22.6-19.14.1
evolution-debugsource - update to 3.22.6-19.14.1
evolution-devel - update to 3.22.6-19.14.1
evolution - update to 3.22.6-19.14.1
evolution-lang - update to 3.22.6-19.14.1