Opened 10 months ago

Closed 10 months ago

Last modified 8 months ago

#22512 closed enhancement (fixed)

thunderbird-140.6.0esr

Reported by: Joe Locash Owned by: zeckma
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

Security fixes: ​https://www.mozilla.org/en-US/security/advisories/mfsa2025-96/

  • CVE-2025-14321: Use-after-free in the WebRTC: Signaling component (high)
  • CVE-2025-14322: Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component (high)
  • CVE-2025-14323: Privilege escalation in the DOM: Notifications component (high)
  • CVE-2025-14324: JIT miscompilation in the JavaScript Engine: JIT component (high)
  • CVE-2025-14325: JIT miscompilation in the JavaScript Engine: JIT component (high)
  • CVE-2025-14328: Privilege escalation in the Netmonitor component (moderate)
  • CVE-2025-14329: Privilege escalation in the Netmonitor component (moderate)
  • CVE-2025-14330: JIT miscompilation in the JavaScript Engine: JIT component (moderate)

Change History (5)

comment:1 by zeckma, 10 months ago

Owner: changed from blfs-book to zeckma
Status: new → assigned

comment:2 by zeckma, 10 months ago

Fixed at 42a3d4759550493de84c0b4c3712237f3153c2ae. Leaving open for SA.

comment:3 by zeckma, 10 months ago

Resolution: → fixed
Status: assigned → closed

SA-12.4-057 issued.

comment:4 by zeckma, 10 months ago

These CVEs have also been addressed:

  • CVE-2025-14331 (Moderate): Same-origin policy bypass in the Request Handling component
  • CVE-2025-14333 (Moderate): Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146

I documented them in SA-12.4-057.

comment:5 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.