{"id":"CLSA-2025-1751913634","summary":"xdg-utils: Fix of 2 CVEs","details":"- xdg-email: disable special support for Thunderbird\n  to address following vulnerabilities:\n- CVE-2020-27748: local file inclusion vulnerability\n- CVE-2022-4055: improper parse of mailto URIs allows bypass\n  of Thunderbird security mechanism for attachments","modified":"2026-06-01T00:31:07.917748068Z","published":"2025-07-07T18:40:39Z","upstream":["CVE-2020-27748","CVE-2022-4055"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/almalinux9.2esu/CLSA-2025-1751913634.html"}],"affected":[{"package":{"name":"xdg-utils","ecosystem":"TuxCare:AlmaLinux:9.2","purl":"pkg:rpm/tuxcare/xdg-utils?distro=almalinux-9.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.3-11.el9.tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2025-1751913634.json"}}],"schema_version":"1.7.5"}