Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

SUSE: 2025:01660-1 important: MozillaThunderbird Multiple Threats

suse
Calendar Grey May 22, 2025
Dist Suse Esm H88
Important security patch for Firefox released to tackle various vulnerabilities. Please update to enhance protection.
* bsc#1243216 Cross-References: * CVE-2025-3875 * CVE-2025-3877

Summary

## This update for MozillaThunderbird fixes the following issues: Update to Mozilla Thunderbird 128.10.1. Security fixes: * MFSA 2025-34 (bsc#1243216) * CVE-2025-3875: Sender Spoofing via Malformed From Header in Thunderbird. * CVE-2025-3877: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links. * CVE-2025-3909: JavaScript Execution via Spoofed PDF Attachment and file:/// Link. * CVE-2025-3932: Tracking Links in Attachments Bypassed Remote Content Blocking. Other bug fixes: * Fixed: standalone message windows/tabs that no longer responded after folder compaction. * Fixed: Thunderbird could crash when importing Outlook messages. * Visual and UX improvements. ## Patch Instructions:

References

* bsc#1243216

Cross-

* CVE-2025-3875

* CVE-2025-3877

* CVE-2025-3909

* CVE-2025-3932

CVSS scores:

* CVE-2025-3875 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

* CVE-2025-3877 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

* CVE-2025-3909 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

* CVE-2025-3932 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected Products:

* openSUSE Leap 15.6

* SUSE Linux Enterprise Desktop 15 SP6

* SUSE Linux Enterprise Real Time 15 SP6

* SUSE Linux Enterprise Server 15 SP6

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

* SUSE Linux Enterprise Workstation Extension 15 SP6

* SUSE Package Hub 15 15-SP6

An update that solves four vulnerabilities can now be installed.

##

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:01660-1
Release Date: 2025-05-22T16:01:52Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here