[CLSA-2025:1751913634] xdg-utils: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2025-07-07 18:40:39 UTC
Description:
- xdg-email: disable special support for Thunderbird to address following vulnerabilities: - CVE-2020-27748: local file inclusion vulnerability - CVE-2022-4055: improper parse of mailto URIs allows bypass of Thunderbird security mechanism for attachments
Updated packages:
  • xdg-utils-1.1.3-11.el9.tuxcare.els1.noarch.rpm
    sha:9d60c51af7b92d6f3e784cc40cd2372213580cc85f9ee6c8a1e6102ff6cca4d0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.