[DSA 5966-1] thunderbird security update

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5966-1                   [email protected]
https://www.debian.org/security/                     Salvatore Bonaccorso
July 27, 2025                         https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : thunderbird
CVE ID         : CVE-2025-8027 CVE-2025-8028 CVE-2025-8029 CVE-2025-8030
                 CVE-2025-8031 CVE-2025-8032 CVE-2025-8033 CVE-2025-8034
                 CVE-2025-8035

Multiple security issues were discovered in Thunderbird, which could
result in the execution of arbitrary code.

For the stable distribution (bookworm), these problems have been fixed in
version 1:128.13.0esr-1~deb12u1.

We recommend that you upgrade your thunderbird packages.

For the detailed security status of thunderbird please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/thunderbird

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmiF8h1fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0RJfQ//e+1PzqbYWRC0MNJVih2pGBW1Zx3/K6gSW+sTB5nV7QXCVgXp7eywq8HX
35hD0btyhJUygZqyFxx/81MA9ac8LvDVmGmgp2PX1ggkpX4nbN3OEC3ZQyedTWyn
V20DO0Y6qKKNga6HXMdYsMGPDg1uLkgO8cvrpKcSwO7otfjYCv1uE+qsgwWpSw+y
LYG1m67CC6IJ+jYcKceuff2xGL0lhiHQhpBKhWKh5CjfH3vTBUL68tDEHcuDxr9V
j9aSDKzy30JOem/xinI5fVb/+qJ4oSo5SZzthVnXaaQFdy1jKALlEkqn/QPmBcGU
0FEHS+p+H9YNA34hxkRReNR1z5dfpx1zAFMaG37HcAweDX43hOE6/qDh0LkDa/CY
NTN4wY9oc8xWwiH0+jYkf/E/1STvtVtqQHcBjCIB6RRcNdtga1npmhTzqUWtdpZX
3zPUu2wru1Ce80SHJf5aZgb30Vx8UOQ7wnoQAjWjEkLGw6omgRBsukU8Dph6h6sH
95b03NbjwkLLCrm11PVWIv0uLE/V1Mcvo3qAa4fqITT70BpAtpz4bhALQPJqoKZz
8SsdLEMChyyH7yc4bMV9xq3YSjD95U9tVx6a6eYGLgXu1rhmyUu3CZjwg8+lJSLG
jDBigmvkag62jPLhUPYYWjjfXO9xZK2qeenE696lvKZYq2/5G4I=
=ZOxl
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.