File _patchinfo of Package patchinfo.38873

<patchinfo incident="38873">
  <issue tracker="bnc" id="1243303">VUL-0: CVE-2025-4918,CVE-2025-4919: MozillaFirefox,firefox-esr,MozillaThunderbird: out-of-bounds accesses (MFSA 2025-36, MFSA 2025-37,MFSA 2025-38)</issue>
  <issue tracker="cve" id="2025-4919"/>
  <issue tracker="cve" id="2025-4918"/>
  <packager>MSirringhaus</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for MozillaThunderbird</summary>
  <description>This update for MozillaThunderbird fixes the following issues:

Update to Mozilla Thunderbird 128.10.2 (MFSA 2025-40, bsc#1243303):

Security fixes:

 - CVE-2025-4918: Out-of-bounds access when resolving Promise objects (bmo#1966612)
 - CVE-2025-4919: Out-of-bounds access when optimizing linear sums (bmo#1966614)

Other fixes:

 - Messages could not be viewed if the profile used a UNC path (bmo#1966256)
 - Visual and UX improvements (bmo#1964156)
</description>
</patchinfo>
openSUSE Build Service is sponsored by