[CLSA-2026:1789566857] Fix CVE(s): CVE-2022-4055
Type:
security
Severity:
Important
Release date:
2026-09-16 13:54:28 UTC
Description:
* SECURITY UPDATE: a mailto: URI could silently attach a local file when Thunderbird was the configured handler - debian/patches/CVE-2022-4055.patch: remove the Thunderbird special case (run_thunderbird() and its callers) from scripts/xdg-email.in, so mailto: URIs go to the desktop handler and no URI field is parsed; the --attach option is dropped with it - debian/patches/tests-xdg-email-thunderbird-passthrough.patch: rewrite the autotest case that asserted the removed Thunderbird path so it asserts the fixed behaviour instead - CVE-2022-4055: unquoted subject= and body= in run_thunderbird() let a mailto: URI append a -compose attachment= argument - CVE-2020-27748: the attach= field of a mailto: URI was passed straight through to -compose attachment=
CVEs fixed:
Updated packages:
  • xdg-utils_1.1.3-4.1+tuxcare.els1_all.deb
    sha:cd97cff3b1983d5a574189d1ebfed41ae2e5837d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.