[DSA 5921-1] thunderbird security update

Moritz Muehlenhoff <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5921-1                   [email protected]
https://www.debian.org/security/                       Moritz Muehlenhoff
May 16, 2025                          https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : thunderbird
CVE ID         : CVE-2025-3875 CVE-2025-3877 CVE-2025-3909 CVE-2025-3932

Multiple security issues were discovered in Thunderbird, which could
result in spoofing of From: mail headers, execution of JavaScript or
information disclosure.

For the stable distribution (bookworm), these problems have been fixed in
version 1:128.10.1esr-1~deb12u1.

We recommend that you upgrade your thunderbird packages.

For the detailed security status of thunderbird please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/thunderbird

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmgnj+0ACgkQEMKTtsN8
TjaeFBAAh3eWJ9Lnkevk8a486b1Iz5t+L4384QjQwklPMRmJRHdiodBvNl8G91ZJ
8COQBLMC8N3xbgoSIFmCVlJMENADGNjHM1NOiLNmcy1lF1Ek7QjVmKC/K9EEpljj
g+3HbkBRhDHG967O9oumIGOWbyzIfJPlwKBQtdjBLiSVN3EwdV/FGpDz5YZbM+BW
nhhtwJ2v/zoq/5m+1McJrqxvkvdScf2MOILsIzSPmL/+I5t2/Kdec7sKsPylOlxb
Lptlu/80OmCPfiNFEl7Zee5s9UqYSPW/4ykJLY6TRcZKlaV7loNCW7OtR1ycIQfy
NI0AyFFxAd3dCc/wfp1xcT9BwdlyCpm7tu6FMft24+GJxEgN0x/E9paO7YZOvly4
sUXKCfvBEUK7wpsJkBtXNwLOm9TDF+0gMpb8sTO3VHLlWKYRNWQ4VL7WB1Y2xHol
dYx+CeZkNXOhbgGdl2NJuwZc+A1wbNNwVfX5c9WvGaljbLNYM6stFEwc8M03TeHV
Zc9kH2LTXhbdfoBLhUCNzOt+iZrYxm6vy7dvb50v2xWphVOr5NgDSFwf7S3I9OvK
ULnso7a7WUVrWV69151tJ1clxAQgHa1Cj8ENMtbgfHOQG+iUVqh+1jls5Ivns9SI
whNEFC4EqErBsewsqor2Bve1zsyDeoywZCxByFHaDUHldwkxFkw=
=LU0K
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.