File _patchinfo of Package patchinfo.38797
<patchinfo incident="38797"> <issue tracker="bnc" id="1243216">VUL-0: CVE-2025-3875,CVE-2025-3877,CVE-2025-3909,CVE-2025-3932: MozillaThunderbird: update to 138.0.1 and 128.10.1esr</issue> <issue tracker="cve" id="2025-3932"/> <issue tracker="cve" id="2025-3909"/> <issue tracker="cve" id="2025-3877"/> <issue tracker="cve" id="2025-3875"/> <packager>cgrobertson</packager> <rating>important</rating> <category>security</category> <summary>Security update for MozillaThunderbird</summary> <description>This update for MozillaThunderbird fixes the following issues: Update to Mozilla Thunderbird 128.10.1. Security fixes: - MFSA 2025-34 (bsc#1243216) * CVE-2025-3875: Sender Spoofing via Malformed From Header in Thunderbird. * CVE-2025-3877: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links. * CVE-2025-3909: JavaScript Execution via Spoofed PDF Attachment and file:/// Link. * CVE-2025-3932: Tracking Links in Attachments Bypassed Remote Content Blocking. Other bug fixes: - Fixed: standalone message windows/tabs that no longer responded after folder compaction. - Fixed: Thunderbird could crash when importing Outlook messages. - Visual and UX improvements. </description> </patchinfo>