Opened 11 months ago

Closed 10 months ago

Last modified 8 months ago

#22381 closed enhancement (fixed)

thunderbird-140.5.0esr

Reported by: zeckma Owned by: zeckma
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New minor version. Assuming most security fixes will be in this release as in firefox-140.5.0esr.

Change History (5)

comment:1 by zeckma, 11 months ago

Severity: critical → normal

comment:2 by zeckma, 11 months ago

Changes


Normal changes

  • Fixed: Could not drag and drop ICS file to Today Pane
  • Fixed: With Thunderbird closed, clicking a mailto: link to send signed message failed
  • Fixed: Upgrade from 128.x->140.x broke authentication for @att.net using Yahoo backend

Security Fixes

  • Rating: High
  • Total: 9; High: 2; Moderate: 6; Low: 1
  • CVE-2025-13012 (High): Race condition in the Graphics component
  • CVE-2025-13016 (High): Incorrect boundary conditions in the JavaScript: WebAssembly component
  • CVE-2025-13017 (Moderate): Same-origin policy bypass in the DOM: Notifications component
  • CVE-2025-13018 (Moderate): Mitigation bypass in the DOM: Security component
  • CVE-2025-13019 (Moderate): Same-origin policy bypass in the DOM: Workers component
  • CVE-2025-13013 (Moderate): Mitigation bypass in the DOM: Core & HTML component
  • CVE-2025-13020 (Moderate): Use-after-free in the WebRTC: Audio/Video component
  • CVE-2025-13014 (Moderate): Use-after-free in the Audio/Video component
  • CVE-2025-13015 (Low): Spoofing issue in Thunderbird
Last edited 11 months ago by zeckma (previous) (diff)

comment:3 by zeckma, 10 months ago

Fixed at 80225d677452d59f31755d466771334ddc28d6dd. Leaving open for SA issuing, I'll handle it.

comment:4 by zeckma, 10 months ago

Resolution: → fixed
Status: assigned → closed

SA-12.4-044 filed.

comment:5 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.