INFSA-2025:14743: thunderbird security update
Information about definition
Identificator: INFSA-2025:14743
Type: security
Release date: 2025-09-04 22:13:51 UTC
Information about package
Mozilla Thunderbird is a standalone mail and newsgroup client.
Vulnerabilities description
- CVE-2025-9179
A flaw was found in Thunderbird and Firefox. The Mozilla Foundation's Security Advisory describes the following issue: An attacker is able to perform memory corruption in the GMP process which process encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process.
- CVE-2025-9180
A flaw was found in Thunderbird and Firefox. The Mozilla Foundation's Security Advisory describes the following issue: Same-origin policy bypass in the Graphics: Canvas2D component.
- CVE-2025-9181
A flaw was found in Thunderbird and Firefox. The Mozilla Foundation's Security Advisory describes the following issue: Uninitialized memory in the JavaScript Engine component.
- CVE-2025-9182
A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: Denial-of-service due to out-of-memory in the Graphics: WebRender component.
- CVE-2025-9185
A flaw was found in Thunderbird and Firefox. The Mozilla Foundation's Security Advisory describes the following issue: Memory safety bugs are present in the following versions: Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141, and Thunderbird 141. Some of these bugs showed evidence of memory corruption, and we presume that with enough effort, some of these could have been exploited to run arbitrary code.
Severity level
CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
---|---|---|---|
NIST — CVE-2025-9179
|
no information | 7.5 | no information |
NIST — CVE-2025-9180
|
no information | 7.5 | no information |
NIST — CVE-2025-9181
|
no information | 6.1 | no information |
NIST — CVE-2025-9182
|
no information | 3.4 | no information |
NIST — CVE-2025-9185
|
no information | 7.5 | no information |
Updated packages