Opened 3 months ago
Closed 2 months ago
#23539 closed enhancement (fixed)
thunderbird-140.12.1esr
| Reported by: | Joe Locash | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | high | Milestone: | 98-Security |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
Security fixes:
- CVE-2026-57962: Denial-of-service via malicious LDAP address-book server (medium)
- CVE-2026-57963: Chat UI manipulation by injection (high)
https://www.mozilla.org/en-US/security/advisories/mfsa2026-64/
Change History (3)
comment:1 by , 3 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 3 months ago
| Milestone: | 13.1 → 98-Security |
|---|---|
| Owner: | changed from to |
| Status: | assigned → new |
comment:3 by , 2 months ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Advisory sa-13.0-145 covering both TB 140.12.0esr and 140.12.1esr has been issued.
Note:
See TracTickets
for help on using tickets.

Fixed at 5d2b60867c. Leaving open for SA.