Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:1157-1

Опубликовано: 07 апр. 2025
Источник: suse-cvrf

Описание

Security update for MozillaThunderbird

This update for MozillaThunderbird fixes the following issues:

  • Mozilla Thunderbird ESR 128.9 MFSA 2025-24 (bsc#1240083)
    • CVE-2025-3028: Use-after-free triggered by XSLTProcessor
    • CVE-2025-3029: URL Bar Spoofing via non-BMP Unicode characters
    • CVE-2025-3030: Memory safety bugs fixed in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9

Other fixes:

  • new: Thunderbird now has a notification system for real-time desktop alerts
  • fixed: Data corruption occurred when compacting IMAP Drafts folder after saving a message
  • fixed: Right-clicking 'Decrypt and Save As...' on an attachment file failed.
  • fixed: Thunderbird could crash when importing mail
  • fixed: Sort indicators were missing on the calendar events list.

Список пакетов

SUSE Linux Enterprise Module for Package Hub 15 SP6
MozillaThunderbird-128.9.0-150200.8.206.1
MozillaThunderbird-translations-common-128.9.0-150200.8.206.1
MozillaThunderbird-translations-other-128.9.0-150200.8.206.1
SUSE Linux Enterprise Workstation Extension 15 SP6
MozillaThunderbird-128.9.0-150200.8.206.1
MozillaThunderbird-translations-common-128.9.0-150200.8.206.1
MozillaThunderbird-translations-other-128.9.0-150200.8.206.1
openSUSE Leap 15.6
MozillaThunderbird-128.9.0-150200.8.206.1
MozillaThunderbird-translations-common-128.9.0-150200.8.206.1
MozillaThunderbird-translations-other-128.9.0-150200.8.206.1

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-128.9.0-150200.8.206.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-128.9.0-150200.8.206.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-128.9.0-150200.8.206.1
SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-128.9.0-150200.8.206.1

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-128.9.0-150200.8.206.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-128.9.0-150200.8.206.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-128.9.0-150200.8.206.1
SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-128.9.0-150200.8.206.1

Ссылки

Описание

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-128.9.0-150200.8.206.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-128.9.0-150200.8.206.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-128.9.0-150200.8.206.1
SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-128.9.0-150200.8.206.1

Ссылки
Уязвимость SUSE-SU-2025:1157-1