Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 9: 2025-0168 high: thunderbird sender spoofing and leaks

mageia
Calendar Grey May 27, 2025
Dist Mageia Esm H88
The latest Thunderbird updates resolve issues related to authentication and insecure file retrieval, enhancing user protection.
Sender Spoofing via Malformed From Header in Thunderbird

Summary

Sender Spoofing via Malformed From Header in Thunderbird. (CVE-2025-3875) Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links. (CVE-2025-3877) JavaScript Execution via Spoofed PDF Attachment and file:/// Link. (CVE-2025-3909) Tracking Links in Attachments Bypassed Remote Content Blocking. (CVE-2025-3932) Out-of-bounds access when resolving Promise objects. (CVE-2025-4918) Out-of-bounds access when optimizing linear sums. (CVE-2025-4919)

References

- https://bugs.mageia.org/show_bug.cgi?id=34288

- https://www.thunderbird.net/en-US/thunderbird/128.10.1esr/releasenotes/

- https://www.mozilla.org/en-US/security/advisories/mfsa2025-34/

- https://www.thunderbird.net/en-US/thunderbird/128.10.2esr/releasenotes/

- https://www.thunderbird.net/en-US/thunderbird/128.10.2esr/releasenotes/

- https://www.cve.org/CVERecord?id=CVE-2025-3875

- https://www.cve.org/CVERecord?id=CVE-2025-3877

- https://www.cve.org/CVERecord?id=CVE-2025-3909

- https://www.cve.org/CVERecord?id=CVE-2025-3932

- https://www.cve.org/CVERecord?id=CVE-2025-4918

- https://www.cve.org/CVERecord?id=CVE-2025-4919

Resolution

SRPMS

- 9/core/thunderbird-128.10.2-1.mga9

- 9/core/thunderbird-l10n-128.10.2-1.mga9

Publication date: 27 May 2025
URL: https://advisories.mageia.org/MGASA-2025-0168.html
Type: security
CVE: CVE-2025-3875, CVE-2025-3877, CVE-2025-3909, CVE-2025-3932, CVE-2025-4918, CVE-2025-4919

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here