Opened 14 months ago
Closed 14 months ago
#21998 closed enhancement (fixed)
thunderbird-140.2.0esr
| Reported by: | Joe Locash | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | high | Milestone: | 12.4 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
What’s Fixed
- Users were unable to use Fastmail calendars due to missing OAuth settings
- Account setup error handling was broken for Account hub
- Menu bar was hidden after updating from 128esr to 140esr
Security fixes https://www.mozilla.org/en-US/security/advisories/mfsa2025-72/
- CVE-2025-9179: Sandbox escape due to invalid pointer in the Audio/Video: GMP component (high)
- CVE-2025-9180: Same-origin policy bypass in the Graphics: Canvas2D component
(high)
- CVE-2025-9181: Uninitialized memory in the JavaScript Engine component (moderate)
- CVE-2025-9182: Denial-of-service due to out-of-memory in the Graphics: WebRender component (low)
- CVE-2025-9184: Memory safety bugs fixed in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142 (high)
- CVE-2025-9185: Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142 (high)
Change History (2)
comment:1 by , 14 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 14 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Note:
See TracTickets
for help on using tickets.

Fixed at 57f80a1991f9475ea90a3947e8022ae9b961a9bd
SA-12.3-096 issued