#21714 closed enhancement (fixed)

thunderbird-128.11.1esr

Reported by: Joe Locash Owned by: zeckma
Priority: elevated Milestone: 12.4
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

Security fixes

Mozilla Foundation Security Advisory 2025-49

​https://www.mozilla.org/en-US/security/advisories/mfsa2025-49/

  • CVE-2025-5986: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links (high)

Change History (3)

comment:1 by zeckma, 16 months ago

Owner: changed from blfs-book to zeckma
Status: new → assigned

comment:2 by zeckma, 16 months ago

This was a vulnerability that was claimed to be fixed in Thunderbird-128.10.2esr. But this was not the case. As such, it is a 22-day old vulnerability.

comment:3 by zeckma, 16 months ago

Resolution: → fixed
Status: assigned → closed
Note: See TracTickets for help on using tickets.