Red Hat Security Advisory: thunderbird security update
🔗 CVE IDs covered (13)
📋 Description
CVE-2025-3875 — thunderbird: Sender Spoofing via Malformed From Header in Thunderbird CVE-2025-3877 — thunderbird: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links CVE-2025-3909 — thunderbird: JavaScript Execution via Spoofed PDF Attachment and file:/// Link CVE-2025-3932 — thunderbird: Tracking Links in Attachments Bypassed Remote Content Blocking CVE-2025-4918 — firefox: thunderbird: Out-of-bounds access when resolving Promise objects CVE-2025-4919 — firefox: thunderbird: Out-of-bounds access when optimizing linear sums CVE-2025-5263 — firefox: thunderbird: Error handling for script execution was incorrectly isolated from web content CVE-2025-5264 — firefox: thunderbird: Potential local code execution in “Copy as cURL” command CVE-2025-5266 — firefox: thunderbird: Script element events leaked cross-origin resource status CVE-2025-5267 — firefox: thunderbird: Clickjacking vulnerability could have led to leaking saved payment card details CVE-2025-5268 — firefox: thunderbird: Memory safety bugs CVE-2025-5269 — firefox: thunderbird: Memory safety bug CVE-2025-5283 — libvpx: Double-free in libvpx encoder
🎯 Affected products14
- Red Hat Enterprise Linux AppStream (v. 8)
- thunderbird-0:128.11.0-1.el8_10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- thunderbird-0:128.11.0-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
- thunderbird-0:128.11.0-1.el8_10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
- thunderbird-0:128.11.0-1.el8_10.src as a component of Red Hat Enterprise Linux AppStream (v. 8)
- thunderbird-0:128.11.0-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- thunderbird-debuginfo-0:128.11.0-1.el8_10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- thunderbird-debuginfo-0:128.11.0-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
- thunderbird-debuginfo-0:128.11.0-1.el8_10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
- thunderbird-debuginfo-0:128.11.0-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- thunderbird-debugsource-0:128.11.0-1.el8_10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
- thunderbird-debugsource-0:128.11.0-1.el8_10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
- thunderbird-debugsource-0:128.11.0-1.el8_10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
- thunderbird-debugsource-0:128.11.0-1.el8_10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. Workaround: Mitigation is either unavailable or does not meet Red Hat Product Security standards for usability, deployment, applicability, or stability.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2025:8756
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2366283
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2366287
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2366291
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2366297
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2367016
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2367018
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2368750
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2368751
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2368752
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2368755
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2368756
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2368757
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_8756.json