#21998 closed enhancement (fixed)

thunderbird-140.2.0esr

Reported by: Joe Locash Owned by: Douglas R. Reno
Priority: high Milestone: 12.4
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

What’s Fixed

  • Users were unable to use Fastmail calendars due to missing OAuth settings
  • Account setup error handling was broken for Account hub
  • Menu bar was hidden after updating from 128esr to 140esr

Security fixes ​https://www.mozilla.org/en-US/security/advisories/mfsa2025-72/

  • CVE-2025-9179: Sandbox escape due to invalid pointer in the Audio/Video: GMP component (high)
  • CVE-2025-9180: Same-origin policy bypass in the Graphics: Canvas2D component

(high)

  • CVE-2025-9181: Uninitialized memory in the JavaScript Engine component (moderate)
  • CVE-2025-9182: Denial-of-service due to out-of-memory in the Graphics: WebRender component (low)
  • CVE-2025-9184: Memory safety bugs fixed in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142 (high)
  • CVE-2025-9185: Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142 (high)

Change History (2)

comment:1 by Douglas R. Reno, 14 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:2 by Douglas R. Reno, 14 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at 57f80a1991f9475ea90a3947e8022ae9b961a9bd

SA-12.3-096 issued

Note: See TracTickets for help on using tickets.