#22512 closed enhancement (fixed)
thunderbird-140.6.0esr
| Reported by: | Joe Locash | Owned by: | zeckma |
|---|---|---|---|
| Priority: | high | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
Security fixes: https://www.mozilla.org/en-US/security/advisories/mfsa2025-96/
- CVE-2025-14321: Use-after-free in the WebRTC: Signaling component (high)
- CVE-2025-14322: Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component (high)
- CVE-2025-14323: Privilege escalation in the DOM: Notifications component (high)
- CVE-2025-14324: JIT miscompilation in the JavaScript Engine: JIT component (high)
- CVE-2025-14325: JIT miscompilation in the JavaScript Engine: JIT component (high)
- CVE-2025-14328: Privilege escalation in the Netmonitor component (moderate)
- CVE-2025-14329: Privilege escalation in the Netmonitor component (moderate)
- CVE-2025-14330: JIT miscompilation in the JavaScript Engine: JIT component (moderate)
Change History (5)
comment:1 by , 10 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 10 months ago
comment:4 by , 10 months ago
These CVEs have also been addressed:
- CVE-2025-14331 (Moderate): Same-origin policy bypass in the Request Handling component
- CVE-2025-14333 (Moderate): Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146
I documented them in SA-12.4-057.
Note:
See TracTickets
for help on using tickets.

Fixed at 42a3d4759550493de84c0b4c3712237f3153c2ae. Leaving open for SA.