#22148 closed enhancement (fixed)
thunderbird-140.3.0esr
| Reported by: | Joe Locash | Owned by: | zeckma |
|---|---|---|---|
| Priority: | high | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
What’s Fixed
- Right-clicking 'List-ID' -> 'Unsubscribe' created double encoded draft subject
- Thunderbird could crash on startup
- Thunderbird could crash when importing mail
- Opening Website header link in RSS feed incorrectly re-encoded URL parameters
Security fixes
https://www.mozilla.org/en-US/security/advisories/mfsa2025-78/
- CVE-2025-10527: Sandbox escape due to use-after-free in the Graphics: Canvas2D component (high)
- CVE-2025-10528: Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component (high)
- CVE-2025-10529: Same-origin policy bypass in the Layout component (moderate)
- CVE-2025-10532: Incorrect boundary conditions in the JavaScript: GC component (moderate)
- CVE-2025-10533: Integer overflow in the SVG component (moderate)
- CVE-2025-10536: Information disclosure in the Networking: Cache component (low)
- CVE-2025-10537: Memory safety bugs fixed in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143 (high)
Change History (5)
comment:1 by , 13 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 13 months ago
comment:3 by , 13 months ago
Fixed at 2b75a276c15857d7f6743cb7c176ec46e21fc110. Leaving open for SA issuing.
Note:
See TracTickets
for help on using tickets.

Thanks for the report as always, Joe!