INFSA-2025:7672: xdg-utils security update

Information about definition

Identificator: INFSA-2025:7672

Type: security

Release date: 2025-06-10 08:40:26 UTC

Information about package

The xdg-utils package is a set of simple scripts that provide basic desktop integration functions for any Free Desktop.

Vulnerabilities description

  • CVE-2022-4055

    When xdg-mail is configured to use thunderbird for mailto URLs, improper parsing of the URL can lead to additional headers being passed to thunderbird that should not be included per RFC 2368. An attacker can use this method to create a mailto URL that looks safe to users, but will actually attach files when clicked.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
NIST — CVE-2022-4055
no information 7.4 no information
Critical, important, moderate, low

Updated packages