File _patchinfo of Package patchinfo.38873
<patchinfo incident="38873">
<issue tracker="bnc" id="1243303">VUL-0: CVE-2025-4918,CVE-2025-4919: MozillaFirefox,firefox-esr,MozillaThunderbird: out-of-bounds accesses (MFSA 2025-36, MFSA 2025-37,MFSA 2025-38)</issue>
<issue tracker="cve" id="2025-4919"/>
<issue tracker="cve" id="2025-4918"/>
<packager>MSirringhaus</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for MozillaThunderbird</summary>
<description>This update for MozillaThunderbird fixes the following issues:
Update to Mozilla Thunderbird 128.10.2 (MFSA 2025-40, bsc#1243303):
Security fixes:
- CVE-2025-4918: Out-of-bounds access when resolving Promise objects (bmo#1966612)
- CVE-2025-4919: Out-of-bounds access when optimizing linear sums (bmo#1966614)
Other fixes:
- Messages could not be viewed if the profile used a UNC path (bmo#1966256)
- Visual and UX improvements (bmo#1964156)
</description>
</patchinfo>