RHSA-2025:8594: Important: thunderbird security update
Important: thunderbird security update
Other sources
Mozilla Thunderbird is a standalone mail and newsgroup client.Security Fix(es): thunderbird: JavaScript Execution via Spoofed PDF Attachment and file:/// Link (CVE-2025-3909) thunderbird: Sender Spoofing via Malformed From Header in Thunderbird (CVE-2025-3875) thunderbird: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links (CVE-2025-3877) thunderbird: Tracking Links in Attachments Bypassed Remote Content Blocking (CVE-2025-3932) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:8594?
The severity of RHSA-2025:8594 is classified as important.
How do I fix RHSA-2025:8594?
You can fix RHSA-2025:8594 by updating to the Thunderbird version 128.10.1-1.el8_6.
What vulnerabilities are addressed in RHSA-2025:8594?
RHSA-2025:8594 addresses vulnerabilities such as JavaScript Execution via Spoofed PDF Attachment and file:/// Link (CVE-2025-3909) and Sender Spoofing via Malformed From Header.
Which products are affected by RHSA-2025:8594?
RHSA-2025:8594 affects multiple versions of the Red Hat Enterprise Linux Server including the TUS and Update Services for SAP Solutions.
Do I need to restart my system after applying RHSA-2025:8594?
It is recommended to restart your system after applying security updates like RHSA-2025:8594 to ensure all changes take effect.