Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

openSUSE: 2025:0080-1 important: MozillaThunderbird Security Update

opensuse
Calendar Grey January 13, 2025
Dist Opensuse Esm H88
This critical security patch for Mozilla Firefox resolves several vulnerabilities in Ubuntu, prioritizing user protection.
An update that solves seven vulnerabilities can now be installed.

Description

This update for MozillaThunderbird fixes the following issues:

Update to Mozilla Thunderbird ESR 128.6 (MFSA 2025-05, bsc#1234991)

Security fixes:

* CVE-2025-0237 (bmo#1915257) WebChannel APIs susceptible to confused deputy

attack

* CVE-2025-0238 (bmo#1915535) Use-after-free when breaking lines in text

* CVE-2025-0239 (bmo#1929156) Alt-Svc ALPN validation failure when redirected

* CVE-2025-0240 (bmo#1929623) Compartment mismatch when parsing JavaScript

JSON module

* CVE-2025-0241 (bmo#1933023) Memory corruption when using JavaScript Text

Segmentation

* CVE-2025-0242 (bmo#1874523, bmo#1926454, bmo#1931873, bmo#1932169) Memory

safety bugs fixed in Firefox 134, Thunderbird 134, Firefox ESR 115.19,

Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6

* CVE-2025-0243 (bmo#1827142, bmo#1932783) Memory safety bugs fixed in Firefox

134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6

Other fixes:

* fixed: New mail notification...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.6

zypper in -t patch openSUSE-SLE-15.6-2025-80=1

* SUSE Package Hub 15 15-SP6

zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-80=1

* SUSE Linux Enterprise Workstation Extension 15 SP6

zypper in -t patch SUSE-SLE-Product-WE-15-SP6-2025-80=1

Package List

* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64)

* MozillaThunderbird-128.6.0-150200.8.197.1

* MozillaThunderbird-debuginfo-128.6.0-150200.8.197.1

* MozillaThunderbird-debugsource-128.6.0-150200.8.197.1

* MozillaThunderbird-translations-common-128.6.0-150200.8.197.1

* MozillaThunderbird-translations-other-128.6.0-150200.8.197.1

* SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x)

* MozillaThunderbird-128.6.0-150200.8.197.1

* MozillaThunderbird-debuginfo-128.6.0-150200.8.197.1

* MozillaThunderbird-debugsource-128.6.0-150200.8.197.1

* MozillaThunderbird-translations-common-128.6.0-150200.8.197.1

* MozillaThunderbird-translations-other-128.6.0-150200.8.197.1

* SUSE Linux Enterprise Workstation Extension 15 SP6 (x86_64)

* MozillaThunderbird-128.6.0-150200.8.197.1

* MozillaThunderbird-debuginfo-128.6.0-150200.8.197.1

* MozillaThunderbird-debugsource-128.6.0-150200.8.197.1

* MozillaThunderbird-translations-common-128.6.0-150200.8.197.1

* MozillaThunderbird-translations-other-128.6.0-150200.8.197.1

References

* bsc#1234991

## References:

* https://www.suse.com/security/cve/CVE-2025-0237.html

* https://www.suse.com/security/cve/CVE-2025-0238.html

* https://www.suse.com/security/cve/CVE-2025-0239.html

* https://www.suse.com/security/cve/CVE-2025-0240.html

* https://www.suse.com/security/cve/CVE-2025-0241.html

* https://www.suse.com/security/cve/CVE-2025-0242.html

* https://www.suse.com/security/cve/CVE-2025-0243.html

* https://bugzilla.suse.com/show_bug.cgi?id=1234991

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:0080-1
Release Date: 2025-01-13T15:31:02Z
Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Workstation Extension 15 SP6 * SUSE Package Hub 15 15-SP6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here