Opened 16 months ago
Closed 16 months ago
#21714 closed enhancement (fixed)
thunderbird-128.11.1esr
| Reported by: | Joe Locash | Owned by: | zeckma |
|---|---|---|---|
| Priority: | elevated | Milestone: | 12.4 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
Security fixes
Mozilla Foundation Security Advisory 2025-49
https://www.mozilla.org/en-US/security/advisories/mfsa2025-49/
- CVE-2025-5986: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links (high)
Change History (3)
comment:1 by , 16 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 16 months ago
comment:3 by , 16 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at 310a2e43840a6b0a67dfffa2baaca9075e218b3f.
Note:
See TracTickets
for help on using tickets.

This was a vulnerability that was claimed to be fixed in Thunderbird-128.10.2esr. But this was not the case. As such, it is a 22-day old vulnerability.