An issue was discovered in GNOME Evolution before 3.35.91. By using the proprietary (non-RFC6068) mailto?attach=… parameter, a website (or other source of mailto links) can make Evolution attach local files or directories to a composed email message without showing a warning to the user, as demonstrated by an attach=. value.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Evolution | Gnome | * | 3.35.91 (excluding) |
Evolution | Ubuntu | bionic | * |
Evolution | Ubuntu | eoan | * |
Evolution | Ubuntu | esm-apps/bionic | * |
Evolution | Ubuntu | esm-apps/focal | * |
Evolution | Ubuntu | esm-apps/jammy | * |
Evolution | Ubuntu | esm-apps/xenial | * |
Evolution | Ubuntu | focal | * |
Evolution | Ubuntu | groovy | * |
Evolution | Ubuntu | hirsute | * |
Evolution | Ubuntu | impish | * |
Evolution | Ubuntu | jammy | * |
Evolution | Ubuntu | kinetic | * |
Evolution | Ubuntu | trusty | * |
Evolution | Ubuntu | upstream | * |
Evolution | Ubuntu | xenial | * |