thunderbird-128.12.0-1.el9_6.ML.1
エラータID: AXSA:2025-10676:17
Mozilla Thunderbird is a standalone mail and newsgroup client.
Security Fix(es):
* thunderbird: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links (CVE-2025-5986)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2025-5986
A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content. This vulnerability affects Thunderbird < 128.11.1 and Thunderbird < 139.0.2.
Update packages.
A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompting, even if auto-saving is disabled. This behavior can be abused to fill the disk with garbage data (e.g. using /dev/urandom on Linux) or to leak Windows credentials via SMB links when the email is viewed in HTML mode. While user interaction is required to download the .pdf file, visual obfuscation can conceal the download trigger. Viewing the email in HTML mode is enough to load external content. This vulnerability affects Thunderbird < 128.11.1 and Thunderbird < 139.0.2.
N/A
SRPMS
- thunderbird-128.12.0-1.el9_6.ML.1.src.rpm
MD5: 898adff7b8dc8e1425208bc564540fcd
SHA-256: 48aa4211854c11dbd6b55247e09e1a7e708c97ad6b3b0ab17e53b3ebf1b1f252
Size: 853.52 MB
Asianux Server 9 for x86_64
- thunderbird-128.12.0-1.el9_6.ML.1.x86_64.rpm
MD5: 469eb7e35c5e2ccee7073afdde86541c
SHA-256: 782d3de231388e7c887af9b2717f21c7eeaf3bda193670153f12363d4ed83038
Size: 118.91 MB