Explore top 10 tips to secure your open-source projects now. Read More
×
Multiple vulnerabilities have been discovered in Mozilla Thunderbird, the worst of which could lead to remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202505-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Mozilla Thunderbird: Multiple Vulnerabilities Date: May 12, 2025 Bugs: #945051, #948114, #951564, #953022 ID: 202505-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in Mozilla Thunderbird, the worst of which could lead to remote code execution. Background ========== Mozilla Thunderbird is a popular open-source email client from the Mozilla project. Affected packages ================= Package Vulnerable Unaffected --------------------------- ------------ ------------ mail-client/thunderbird < 128.9.0 > = 128.9.0 mail-client/thunderbird-bin < 128.9.0 > = 128.9.0 Description =========== Multiple vulnerabilities have been discovered in Mozilla Thunderbird. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All Mozilla Thunderbird users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =mail-client/thunderbird-bin-128.9.0" All Mozilla Thunderbird users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =mail-client/thunderbird-128.9.0" References ========== [ 1 ] CVE-2024-11692 https://nvd.nist.gov/vuln/detail/CVE-2024-11692 [ 2 ] CVE-2024-11694 https://nvd.nist.gov/vuln/detail/CVE-2024-11694 [ 3 ] CVE-2024-11695 https://nvd.nist.gov/vuln/detail/CVE-2024-11695 [ 4 ] CVE-2024-11696 https://nvd.nist.gov/vuln/detail/CVE-2024-11696 [ 5 ] CVE-2024-11697 https://nvd.nist.gov/vuln/detail/CVE-2024-11697 [ 6 ] CVE-2024-11699 https://nvd.nist.gov/vuln/detail/CVE-2024-11699 [ 7 ] CVE-2024-11700 https://nvd.nist.gov/vuln/detail/CVE-2024-11700 [ 8 ] CVE-2024-11701 https://nvd.nist.gov/vuln/detail/CVE-2024-11701 [ 9 ] CVE-2024-11704 https://nvd.nist.gov/vuln/detail/CVE-2024-11704 [ 10 ] CVE-2024-11705 https://nvd.nist.gov/vuln/detail/CVE-2024-11705 [ 11 ] CVE-2024-11706 https://nvd.nist.gov/vuln/detail/CVE-2024-11706 [ 12 ] CVE-2024-11708 https://nvd.nist.gov/vuln/detail/CVE-2024-11708 [ 13 ] CVE-2024-43097 https://nvd.nist.gov/vuln/detail/CVE-2024-43097 [ 14 ] CVE-2024-50336 https://nvd.nist.gov/vuln/detail/CVE-2024-50336 [ 15 ] CVE-2025-0237 https://nvd.nist.gov/vuln/detail/CVE-2025-0237 [ 16 ] CVE-2025-0238 https://nvd.nist.gov/vuln/detail/CVE-2025-0238 [ 17 ] CVE-2025-0239 https://nvd.nist.gov/vuln/detail/CVE-2025-0239 [ 18 ] CVE-2025-0240 https://nvd.nist.gov/vuln/detail/CVE-2025-0240 [ 19 ] CVE-2025-0241 https://nvd.nist.gov/vuln/detail/CVE-2025-0241 [ 20 ] CVE-2025-0242 https://nvd.nist.gov/vuln/detail/CVE-2025-0242 [ 21 ] CVE-2025-0243 https://nvd.nist.gov/vuln/detail/CVE-2025-0243 [ 22 ] CVE-2025-1931 https://nvd.nist.gov/vuln/detail/CVE-2025-1931 [ 23 ] CVE-2025-1932 https://nvd.nist.gov/vuln/detail/CVE-2025-1932 [ 24 ] CVE-2025-1933 https://nvd.nist.gov/vuln/detail/CVE-2025-1933 [ 25 ] CVE-2025-1934 https://nvd.nist.gov/vuln/detail/CVE-2025-1934 [ 26 ] CVE-2025-1935 https://nvd.nist.gov/vuln/detail/CVE-2025-1935 [ 27 ] CVE-2025-1936 https://nvd.nist.gov/vuln/detail/CVE-2025-1936 [ 28 ] CVE-2025-1937 https://nvd.nist.gov/vuln/detail/CVE-2025-1937 [ 29 ] CVE-2025-1938 https://nvd.nist.gov/vuln/detail/CVE-2025-1938 [ 30 ] CVE-2025-3028 https://nvd.nist.gov/vuln/detail/CVE-2025-3028 [ 31 ] CVE-2025-3029 https://nvd.nist.gov/vuln/detail/CVE-2025-3029 [ 32 ] CVE-2025-3030 https://nvd.nist.gov/vuln/detail/CVE-2025-3030 [ 33 ] CVE-2025-3031 https://nvd.nist.gov/vuln/detail/CVE-2025-3031 [ 34 ] CVE-2025-3032 https://nvd.nist.gov/vuln/detail/CVE-2025-3032 [ 35 ] CVE-2025-3034 https://nvd.nist.gov/vuln/detail/CVE-2025-3034 [ 36 ] CVE-2025-26695 https://nvd.nist.gov/vuln/detail/CVE-2025-26695 [ 37 ] CVE-2025-26696 https://nvd.nist.gov/vuln/detail/CVE-2025-26696 [ 38 ] MFSA2024-63 [ 39 ] MFSA2024-64 [ 40 ] MFSA2024-65 [ 41 ] MFSA2024-67 [ 42 ] MFSA2024-68 [ 43 ] MFSA2025-01 [ 44 ] MFSA2025-02 [ 45 ] MFSA2025-05 [ 46 ] MFSA2025-14 [ 47 ] MFSA2025-16 [ 48 ] MFSA2025-18 [ 49 ] MFSA2025-20 [ 50 ] MFSA2025-22 [ 51 ] MFSA2025-23 [ 52 ] MFSA2025-24 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202505-03 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Update to 115.16.1 https://www.thunderbird.net/en-US/thunderbird/115.16.1esr/releasenotes/. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ad738c922d 2024-11-08 01:20:27.286251 -------------------------------------------------------------------------------- Name : thunderbird Product : Fedora 39 Version : 115.16.1 Release : 1.fc39 URL : https://wiki.mozilla.org/Thunderbird:Home Summary : Mozilla Thunderbird mail/newsgroup client Description : Mozilla Thunderbird is a standalone mail and newsgroup client. -------------------------------------------------------------------------------- Update Information: Update to 115.16.1 https://www.thunderbird.net/en-US/thunderbird/115.16.1esr/releasenotes/ -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 30 2024 Eike Rathke - 115.16.1-1 - Update to 115.16.1 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ad738c922d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Version 1.6.8 Managesieve: Protect special scripts in managesieve_kolab_master mode Fix newmail_notifier notification focus in Chrome (#9467) Fix fatal error when parsing some TNEF attachments (#9462) Fix double scrollbar when composing a mail with many plain text lines (#7760). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-2e908e829a 2024-08-15 02:33:16.252055 -------------------------------------------------------------------------------- Name : roundcubemail Product : Fedora 40 Version : 1.6.8 Release : 1.fc40 URL : https://roundcube.net/ Summary : Round Cube Webmail is a browser-based multilingual IMAP client Description : RoundCube Webmail is a browser-based multilingual IMAP client with an application-like user interface. It provides full functionality you expect from an e-mail client, including MIME support, address book, folder manipulation, message searching and spell checking. RoundCube Webmail is written in PHP and requires a database: MySQL, PostgreSQL and SQLite are known to work. The user interface is fully skinnable using XHTML and CSS 2. -------------------------------------------------------------------------------- Update Information: Version 1.6.8 Managesieve: Protect special scripts in managesieve_kolab_master mode Fix newmail_notifier notification focus in Chrome (#9467) Fix fatal error when parsing some TNEF attachments (#9462) Fix double scrollbar when composing a mail with many plain text lines (#7760) Fix decoding mail parts with multiple base64-encoded text blocks (#9290) Fix bug where some messages could get malformed in an import from a MBOX file (#9510) Fix invalid line break characters in multi-line text in Sieve scripts (#9543) Fix bug where "with attachment" filter could fail on some fts engines (#9514) Fix bug where an unhandled exception was caused by an invalid image attachment (#9475) Fix bug where a long subject title could not bedisplayed in some cases (#9416) Fix infinite loop when parsing malformed Sieve script (#9562) Fix bug where imap_conn_option's 'socket' was ignored (#9566) Fix XSS vulnerability in post-processing of sanitized HTML content CVE-2024-42009 Fix XSS vulnerability in serving of attachments other than HTML or SVG CVE-2024-42008 Fix information leak (access to remote content) via insufficient CSS filtering CVE-2024-42010 -------------------------------------------------------------------------------- ChangeLog: * Mon Aug 5 2024 Remi Collet - 1.6.8-1 - update to 1.6.8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2303071 - CVE-2024-42008 roundcubemail: A Cross-Site Scripting vulnerability in rcmail_action_mail_get-> run() in Roundcube [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2303071 [ 2 ] Bug #2303076 - CVE-2024-42009 roundcubemail: A Cross-Site Scripting vulnerability in Roundcube [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2303076 [ 3 ] Bug #2303096 - CVE-2024-42010 roundcubemail: information leak due to insufficient CSS filtering [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2303096 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-2e908e829a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 115.12.1 https://www.thunderbird.net/en-US/thunderbird/115.12.1esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-28/ Update to 115.12.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-28/. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-6de8bb7c1b 2024-06-25 01:05:32.899320 -------------------------------------------------------------------------------- Name : thunderbird Product : Fedora 39 Version : 115.12.1 Release : 1.fc39 URL : https://wiki.mozilla.org/Thunderbird:Home Summary : Mozilla Thunderbird mail/newsgroup client Description : Mozilla Thunderbird is a standalone mail and newsgroup client. -------------------------------------------------------------------------------- Update Information: Update to 115.12.1 https://www.thunderbird.net/en-US/thunderbird/115.12.1esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-28/ Update to 115.12.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-28/ https://www.thunderbird.net/en-US/thunderbird/115.12.0esr/releasenotes/ -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 19 2024 Eike Rathke - 115.12.1-1 - Update to 115.12.1 * Tue Jun 18 2024 Eike Rathke - 115.12.0-3 - Resolves: rhbz#2283993 Allow MOZ_ENABLE_WAYLAND default value override * Wed Jun 12 2024 Eike Rathke - 115.12.0-2 - Update to 115.12.0 * Mon Jun 3 2024 Eike Rathke - 115.11.2-1 - Update to 115.11.2 * Wed May 29 2024 Eike Rathke - 115.11.1-1 - Update to 115.11.1 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-6de8bb7c1b' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Important: thunderbird security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:2888", "synopsis": "Important: thunderbird security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for thunderbird.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Mozilla Thunderbird is a standalone mail and newsgroup client.\n\nThis update upgrades Thunderbird to version 115.11.0.\n\nSecurity Fix(es):\n\n* firefox: Arbitrary JavaScript execution in PDF.js (CVE-2024-4367)\n\n* firefox: IndexedDB files retained in private browsing mode (CVE-2024-4767)\n\n* firefox: Potential permissions request bypass via clickjacking (CVE-2024-4768)\n\n* firefox: Cross-origin responses could be distinguished between script and\nnon-script content-types (CVE-2024-4769)\n\n* firefox: Use-after-free could occur when printing to PDF (CVE-2024-4770)\n\n* firefox: Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and\nThunderbird 115.11 (CVE-2024-4777)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2280382", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2280382", "description": ""}, {"ticket": "2280383", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2280383", "description": ""}, {"ticket": "2280384", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2280384", "description": ""}, {"ticket": "2280385", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2280385", "description": ""}, {"ticket": "2280386", "sourceBy": "Red Hat", "sourceLink":"https://bugzilla.redhat.com/show_bug.cgi?id=2280386", "description": ""}, {"ticket": "2280387", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2280387", "description": ""}], "cves": [{"name": "CVE-2024-4367", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-4367", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-4767", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-4767", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-4768", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-4768", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-4769", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-4769", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-4770", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-4770", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-4777", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-4777", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-06-14T14:00:40.182624Z", "rpms": {"Rocky Linux 9": {"nvras": ["thunderbird-0:115.11.0-1.el9_4.aarch64.rpm", "thunderbird-0:115.11.0-1.el9_4.ppc64le.rpm", "thunderbird-0:115.11.0-1.el9_4.s390x.rpm", "thunderbird-0:115.11.0-1.el9_4.src.rpm", "thunderbird-0:115.11.0-1.el9_4.x86_64.rpm", "thunderbird-debuginfo-0:115.11.0-1.el9_4.aarch64.rpm", "thunderbird-debuginfo-0:115.11.0-1.el9_4.ppc64le.rpm", "thunderbird-debuginfo-0:115.11.0-1.el9_4.s390x.rpm", "thunderbird-debuginfo-0:115.11.0-1.el9_4.x86_64.rpm", "thunderbird-debugsource-0:115.11.0-1.el9_4.aarch64.rpm", "thunderbird-debugsource-0:115.11.0-1.el9_4.ppc64le.rpm","thunderbird-debugsource-0:115.11.0-1.el9_4.s390x.rpm", "thunderbird-debugsource-0:115.11.0-1.el9_4.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Recent security patch for Thunderbird on Rocky Linux 9 addresses critical vulnerabilities in the email application, improving both security and functionality.. Thunderbird Security Update, Important Update, Rocky Linux 9. . Severity: Important. LinuxSecurity.com Team
Update to 2.53.18.2. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-8890015ff3 2024-04-01 00:45:48.184130 -------------------------------------------------------------------------------- Name : seamonkey Product : Fedora 39 Version : 2.53.18.2 Release : 1.fc39 URL : https://www.seamonkey-project.org/ Summary : Web browser, e-mail, news, IRC client, HTML editor Description : SeaMonkey is an all-in-one Internet application suite (previously made popular by Netscape and Mozilla). It includes an Internet browser, advanced e-mail, newsgroup and feed client, a calendar, IRC client, HTML editor and a tool to inspect the DOM for web pages. It is derived from the application formerly known as Mozilla Application Suite. -------------------------------------------------------------------------------- Update Information: Update to 2.53.18.2 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 23 2024 Dmitry Butskoy 2.53.18.2-1 - update to 2.53.18.2 * Sat Jan 27 2024 Fedora Release Engineering - 2.53.18.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-8890015ff3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 2.53.18.2. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-31b196eaf1 2024-04-01 00:15:12.467434 -------------------------------------------------------------------------------- Name : seamonkey Product : Fedora 40 Version : 2.53.18.2 Release : 1.fc40 URL : https://www.seamonkey-project.org/ Summary : Web browser, e-mail, news, IRC client, HTML editor Description : SeaMonkey is an all-in-one Internet application suite (previously made popular by Netscape and Mozilla). It includes an Internet browser, advanced e-mail, newsgroup and feed client, a calendar, IRC client, HTML editor and a tool to inspect the DOM for web pages. It is derived from the application formerly known as Mozilla Application Suite. -------------------------------------------------------------------------------- Update Information: Update to 2.53.18.2 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 23 2024 Dmitry Butskoy 2.53.18.2-1 - update to 2.53.18.2 - add patch for system icu-74.1 (mozbz 1862601) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-31b196eaf1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 115.9.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-14/ https://www.thunderbird.net/en-US/thunderbird/115.9.0/releasenotes/. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-5d080305ab 2024-03-28 01:40:27.506862 -------------------------------------------------------------------------------- Name : thunderbird Product : Fedora 38 Version : 115.9.0 Release : 1.fc38 URL : https://wiki.mozilla.org/Thunderbird:Home_Page Summary : Mozilla Thunderbird mail/newsgroup client Description : Mozilla Thunderbird is a standalone mail and newsgroup client. -------------------------------------------------------------------------------- Update Information: Update to 115.9.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-14/ https://www.thunderbird.net/en-US/thunderbird/115.9.0/releasenotes/ -------------------------------------------------------------------------------- ChangeLog: * Mon Mar 18 2024 Eike Rathke - 115.9.0-1 - Update to 115.9.0 - Fix expat CVE-2023-52425 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-5d080305ab' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.