RHSA-2025:3628: Important: firefox security update
Important: firefox security update
Other sources
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability.Security Fix(es): firefox: thunderbird: URL Bar Spoofing via non-BMP Unicode characters (CVE-2025-3029) firefox: thunderbird: Use-after-free triggered by XSLTProcessor (CVE-2025-3028) firefox: thunderbird: Memory safety bugs fixed in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9 (CVE-2025-3030) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:3628?
RHSA-2025:3628 is classified as an important security update.
What vulnerabilities are addressed in RHSA-2025:3628?
RHSA-2025:3628 addresses URL Bar Spoofing via non-BMP Unicode characters identified as CVE-2025-3029.
How do I fix the vulnerability identified in RHSA-2025:3628?
To fix the vulnerability in RHSA-2025:3628, update Firefox to version 128.9.0-2.el7_9.
Which software is affected by RHSA-2025:3628?
RHSA-2025:3628 affects the Firefox and Firefox-debuginfo packages on Red Hat systems.
Is there a workaround for the issues in RHSA-2025:3628?
There are no suggested workarounds for the vulnerabilities addressed in RHSA-2025:3628; updating is recommended.