[ALSA-2025:1292] Important: thunderbird security update
Type:
security
Severity:
important
Release date:
2025-02-11
Description:
Mozilla Thunderbird is a standalone mail and newsgroup client. Security Fix(es): * firefox: thunderbird: Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7 (CVE-2025-1017) * firefox: thunderbird: Use-after-free in Custom Highlight (CVE-2025-1010) * firefox: thunderbird: Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 115.20, and Thunderbird 128.7 (CVE-2025-1016) * firefox: thunderbird: Potential opening of private browsing tabs in normal browsing windows (CVE-2025-1013) * firefox: thunderbird: A bug in WebAssembly code generation could result in a crash (CVE-2025-1011) * thunderbird: Unsanitized address book fields (CVE-2025-1015) * firefox: thunderbird: Use-after-free in XSLT (CVE-2025-1009) * thunderbird: Address of e-mail sender can be spoofed by malicious email (CVE-2025-0510) * firefox: thunderbird: Certificate length was not properly checked (CVE-2025-1014) * firefox: thunderbird: Use-after-free during concurrent delazification (CVE-2025-1012) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 thunderbird-128.7.0-1.el8_10.alma.1.aarch64.rpm 6083d207cd9d02cc5f6c6ff743c49e3e0a9a19eacadef57ef4e80a3f49a24bb2
ppc64le thunderbird-128.7.0-1.el8_10.alma.1.ppc64le.rpm 046b0fcb9864b617f9eb6b435abf72628197bcd44e54a200625652c88caf9ee6
s390x thunderbird-128.7.0-1.el8_10.alma.1.s390x.rpm f704bab4a2592efd1168324c9fc300d5e3683788f0786e06c20e059cc6b23fdd
x86_64 thunderbird-128.7.0-1.el8_10.alma.1.x86_64.rpm c28b479a9e37d9d1b5c788147aa7cd04287c7504a98c0b40eb1b8c805a7767ef
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.