Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:4195-1

Опубликовано: 24 нояб. 2025
Источник: suse-cvrf

Описание

Security update for MozillaThunderbird

This update for MozillaThunderbird fixes the following issues:

  • Update Mozilla Thunderbird to version 140.5 (bsc#1253188)
  • CVE-2025-13012: Race condition in the Graphics component.
  • CVE-2025-13016: Incorrect boundary conditions in the JavaScript: WebAssembly component.
  • CVE-2025-13017: Same-origin policy bypass in the DOM: Notifications component.
  • CVE-2025-13018: Mitigation bypass in the DOM: Security component.
  • CVE-2025-13019: Same-origin policy bypass in the DOM: Workers component.
  • CVE-2025-13013: Mitigation bypass in the DOM: Core & HTML component.
  • CVE-2025-13020: Use-after-free in the WebRTC: Audio/Video component.
  • CVE-2025-13014: Use-after-free in the Audio/Video component.
  • CVE-2025-13015: Spoofing issue in Thunderbird.

Список пакетов

SUSE Linux Enterprise Module for Package Hub 15 SP6
MozillaThunderbird-140.5.0-150200.8.245.1
MozillaThunderbird-translations-common-140.5.0-150200.8.245.1
MozillaThunderbird-translations-other-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP7
MozillaThunderbird-140.5.0-150200.8.245.1
MozillaThunderbird-translations-common-140.5.0-150200.8.245.1
MozillaThunderbird-translations-other-140.5.0-150200.8.245.1
SUSE Linux Enterprise Workstation Extension 15 SP6
MozillaThunderbird-140.5.0-150200.8.245.1
MozillaThunderbird-translations-common-140.5.0-150200.8.245.1
MozillaThunderbird-translations-other-140.5.0-150200.8.245.1
SUSE Linux Enterprise Workstation Extension 15 SP7
MozillaThunderbird-140.5.0-150200.8.245.1
MozillaThunderbird-translations-common-140.5.0-150200.8.245.1
MozillaThunderbird-translations-other-140.5.0-150200.8.245.1
openSUSE Leap 15.6
MozillaThunderbird-140.5.0-150200.8.245.1
MozillaThunderbird-translations-common-140.5.0-150200.8.245.1
MozillaThunderbird-translations-other-140.5.0-150200.8.245.1

Описание

Race condition in the Graphics component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Firefox ESR < 115.30, Thunderbird < 145, and Thunderbird < 140.5.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:MozillaThunderbird-140.5.0-150200.8.245.1

Ссылки

Описание

Mitigation bypass in the DOM: Core & HTML component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Firefox ESR < 115.30, Thunderbird < 145, and Thunderbird < 140.5.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:MozillaThunderbird-140.5.0-150200.8.245.1

Ссылки

Описание

Use-after-free in the Audio/Video component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Firefox ESR < 115.30, Thunderbird < 145, and Thunderbird < 140.5.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:MozillaThunderbird-140.5.0-150200.8.245.1

Ссылки

Описание

Spoofing issue in Firefox. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Firefox ESR < 115.30, Thunderbird < 145, and Thunderbird < 140.5.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:MozillaThunderbird-140.5.0-150200.8.245.1

Ссылки

Описание

Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Thunderbird < 145, and Thunderbird < 140.5.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:MozillaThunderbird-140.5.0-150200.8.245.1

Ссылки

Описание

Same-origin policy bypass in the DOM: Notifications component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Thunderbird < 145, and Thunderbird < 140.5.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:MozillaThunderbird-140.5.0-150200.8.245.1

Ссылки

Описание

Mitigation bypass in the DOM: Security component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Thunderbird < 145, and Thunderbird < 140.5.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:MozillaThunderbird-140.5.0-150200.8.245.1

Ссылки

Описание

Same-origin policy bypass in the DOM: Workers component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Thunderbird < 145, and Thunderbird < 140.5.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:MozillaThunderbird-140.5.0-150200.8.245.1

Ссылки

Описание

Use-after-free in the WebRTC: Audio/Video component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Thunderbird < 145, and Thunderbird < 140.5.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-140.5.0-150200.8.245.1
SUSE Linux Enterprise Module for Package Hub 15 SP7:MozillaThunderbird-140.5.0-150200.8.245.1

Ссылки
Уязвимость SUSE-SU-2025:4195-1