xdg-utils: improper parse of mailto URIs allows bypass of Thunderbird security mechanism for attachments
Published Nov 18, 2022
7.4
HIGHCVSS 3.1
EPSS 0.68%
Description
When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.
Affected products
- Vendor n/a Product Xdg-Utils Defaultn/a
- Version xdg-utils 1.1.0 to and including 1.1.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Xdg-Utils | n/a |
|
- ≥ 1.1.0 · ≤ 1.1.3
No data.
Red Hat Enterprise Linux 9
xdg-utils-0:1.1.3-13.el9_6
Fixed · RHSA-2025:7672
Red Hat Enterprise Linux 6
xdg-utils
Out of support scope
Red Hat Enterprise Linux 7
xdg-utils
Out of support scope
Red Hat Enterprise Linux 8
xdg-utils
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | xdg-utils-0:1.1.3-13.el9_6 | Fixed | RHSA-2025:7672 |
| Red Hat Enterprise Linux 6 | xdg-utils | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | xdg-utils | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | xdg-utils | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
To exploit this flaw, an attacker would need to convince a user to click on a specially crafted mailto URL. Additionally, the user must have the Thunderbird email client installed and xdg-mail configured to use Thunderbird to handle mailto URLs. Therefore, this vulnerability is rated as moderate rather than important because it requires user interaction and specific system configurations.
Red Hat mitigation
To mitigate this flaw, either: 1. Do not use mailto links at all 2. Always double-check in the user interface that there are no unwanted attachments before sending emails; especially when the email originates from clicking a mailto link.
References (6)
- https://access.redhat.com/security/cve/CVE-2022-4055 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2143792 Issue Tracking
- https://gitlab.freedesktop.org/xdg/xdg-utils/-/issues/205
- https://gitlab.freedesktop.org/xdg/xdg-utils/-/issues/205#note_1494267 ExploitIssue TrackingThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-4055
- https://www.cve.org/CVERecord?id=CVE-2022-4055
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-4055 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2143792 | Issue Tracking | |
| https://gitlab.freedesktop.org/xdg/xdg-utils/-/issues/205 | ||
| https://gitlab.freedesktop.org/xdg/xdg-utils/-/issues/205#note_1494267 | ExploitIssue TrackingThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-4055 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-4055 |
Change history (0)
No recorded changes yet.