Opened 19 months ago

Closed 18 months ago

Last modified 17 months ago

#21375 closed enhancement (fixed)

thunderbird-128.9.1esr

Reported by: Douglas R. Reno Owned by: Douglas R. Reno
Priority: elevated Milestone: 12.4
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New minor version to correspond with Firefox.

What's New

  • Thunderbird now has a notification system for real-time desktop alerts

What's Fixed

  • Data corruption occurred when compacting IMAP Drafts folder after saving a message
  • Right-clicking "Decrypt and Save As..." on an attachment file failed.
  • Thunderbird could crash when importing mail
  • Sort indicators were missing on the calendar events list.
  • Security fixes

Security Fixes

  • CVE-2025-3028: Use-after-free triggered by XSLTProcessor (High)
  • CVE-2025-3029: URL Bar Spoofing via non-BMP Unicode characters (Moderate)
  • CVE-2025-3030: Memory safety bugs fixed in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9 (High)

I suspect CVE-2025-3028 could be exploited via mail which is why the usual tag of these vulnerabilities being difficult to exploit is missing. You'd have to receive an email sent with XHTML, but if you did I could see it triggering the use-after-free while trying to process it.

Change History (6)

comment:1 by Douglas R. Reno, 19 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:2 by Joe Locash, 18 months ago

128.9.1 was released today. Release notes are not available yet so I don't know what's been fixed.

comment:3 by zeckma, 18 months ago

Summary: thunderbird-128.9.0esr → thunderbird-128.9.1esr

comment:4 by zeckma, 18 months ago

128.9.1esr changes:

  • Added delay to built-in notifications when new profile is created in offline mode

comment:5 by Douglas R. Reno, 18 months ago

Resolution: → fixed
Status: assigned → closed

comment:6 by Douglas R. Reno, 17 months ago

SA-12.3-035 issued

Note: See TracTickets for help on using tickets.