compose.php in SquirrelMail 1.4.22 calls unserialize for the $mailtodata value, which originates from an HTTP GET request. This is related to mailto.php. Reference: https://www.openwall.com/lists/oss-security/2020/06/20/1
Created squirrelmail tracking bugs for this issue: Affects: epel-all [bug 1850182] Affects: fedora-all [bug 1850181]
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-14932