Opened 13 months ago

Closed 13 months ago

Last modified 8 months ago

#22148 closed enhancement (fixed)

thunderbird-140.3.0esr

Reported by: Joe Locash Owned by: zeckma
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

What’s Fixed

  • Right-clicking 'List-ID' -> 'Unsubscribe' created double encoded draft subject
  • Thunderbird could crash on startup
  • Thunderbird could crash when importing mail
  • Opening Website header link in RSS feed incorrectly re-encoded URL parameters

Security fixes

​https://www.mozilla.org/en-US/security/advisories/mfsa2025-78/

  • CVE-2025-10527: Sandbox escape due to use-after-free in the Graphics: Canvas2D component (high)
  • CVE-2025-10528: Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component (high)
  • CVE-2025-10529: Same-origin policy bypass in the Layout component (moderate)
  • CVE-2025-10532: Incorrect boundary conditions in the JavaScript: GC component (moderate)
  • CVE-2025-10533: Integer overflow in the SVG component (moderate)
  • CVE-2025-10536: Information disclosure in the Networking: Cache component (low)
  • CVE-2025-10537: Memory safety bugs fixed in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143 (high)

Change History (5)

comment:1 by zeckma, 13 months ago

Owner: changed from blfs-book to zeckma
Status: new → assigned

comment:2 by zeckma, 13 months ago

Thanks for the report as always, Joe!

comment:3 by zeckma, 13 months ago

Fixed at 2b75a276c15857d7f6743cb7c176ec46e21fc110. Leaving open for SA issuing.

comment:4 by zeckma, 13 months ago

Resolution: → fixed
Status: assigned → closed

SA 12.4-003 issued.

comment:5 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.