thunderbird-128.11.0-1.el8_10.ML.1

エラータID: AXSA:2025-10026:12

Release date: 
Tuesday, June 17, 2025 - 17:10
Subject: 
thunderbird-128.11.0-1.el8_10.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Mozilla Thunderbird is a standalone mail and newsgroup client.

Security Fix(es):

thunderbird: JavaScript Execution via Spoofed PDF Attachment and file:///
Link (CVE-2025-3909)
thunderbird: Sender Spoofing via Malformed From Header in Thunderbird
(CVE-2025-3875)
thunderbird: Unsolicited File Download, Disk Space Exhaustion, and
Credential Leakage via mailbox:/// Links (CVE-2025-3877)
thunderbird: Tracking Links in Attachments Bypassed Remote Content Blocking
(CVE-2025-3932)
firefox: thunderbird: Out-of-bounds access when resolving Promise objects
(CVE-2025-4918)
firefox: thunderbird: Out-of-bounds access when optimizing linear sums
(CVE-2025-4919)
firefox: thunderbird: Clickjacking vulnerability could have led to leaking
saved payment card details (CVE-2025-5267)
firefox: thunderbird: Potential local code execution in ?Copy as cURL?
command (CVE-2025-5264)
firefox: thunderbird: Memory safety bugs (CVE-2025-5268)
firefox: thunderbird: Script element events leaked cross-origin resource
status (CVE-2025-5266)
firefox: thunderbird: Error handling for script execution was incorrectly
isolated from web content (CVE-2025-5263)
firefox: thunderbird: Memory safety bug (CVE-2025-5269)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE page(s)
listed in the References section.

CVE(s):
CVE-2025-3875
CVE-2025-3877
CVE-2025-3909
CVE-2025-3932
CVE-2025-4918
CVE-2025-4919
CVE-2025-5263
CVE-2025-5264
CVE-2025-5266
CVE-2025-5267
CVE-2025-5268
CVE-2025-5269

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. thunderbird-128.11.0-1.el8_10.ML.1.src.rpm
    MD5: 10bc763232bf85609c012fbe14ff2346
    SHA-256: c9316633676a3b4a0f7beed6f0aef486138695cf22a7b56f235e55368cd04350
    Size: 854.25 MB

Asianux Server 8 for x86_64
  1. thunderbird-128.11.0-1.el8_10.ML.1.x86_64.rpm
    MD5: e77ca81f16e6e66e05f85fc914e9d0f2
    SHA-256: a614addbdfb6a1554e1d741339f6635b7797c59e5367ebf5a083647cd9a7faa0
    Size: 123.08 MB