{"id":"SUSE-SU-2023:3375-1","summary":"Security update for evolution","details":"This update for evolution fixes the following issues:\n\n- CVE-2020-11879: Fixed issue where websites can attach local files to emails by using a proprietary parameter without warning the user (bsc#1169843).\n- Fix some warnings with newer WebKit\n- Handle frame flattening change in WebKitGTK 2.40 (bsc#1213858)\n","modified":"2026-02-04T04:38:20.918315Z","published":"2023-08-22T15:00:42Z","related":["CVE-2020-11879"],"upstream":["CVE-2020-11879"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20233375-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1169843"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213858"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-11879"}],"affected":[{"package":{"name":"evolution","ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP5","purl":"pkg:rpm/suse/evolution&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.22.6-19.14.1"}]}],"ecosystem_specific":{"binaries":[{"evolution-devel":"3.22.6-19.14.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3375-1.json"}},{"package":{"name":"evolution","ecosystem":"SUSE:Linux Enterprise Workstation Extension 12 SP5","purl":"pkg:rpm/suse/evolution&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.22.6-19.14.1"}]}],"ecosystem_specific":{"binaries":[{"evolution-lang":"3.22.6-19.14.1","evolution":"3.22.6-19.14.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3375-1.json"}}],"schema_version":"1.7.3"}