RHSA-2025:8598: Important: thunderbird security update
Important: thunderbird security update
Other sources
Mozilla Thunderbird is a standalone mail and newsgroup client.<br>Security Fix(es):<br><li> firefox: thunderbird: Out-of-bounds access when resolving Promise objects (CVE-2025-4918)</li> <li> firefox: thunderbird: Out-of-bounds access when optimizing linear sums (CVE-2025-4919)</li> <li> firefox: thunderbird: Clickjacking vulnerability could have led to leaking saved payment card details (CVE-2025-5267)</li> <li> firefox: thunderbird: Potential local code execution in ?Copy as cURL? command (CVE-2025-5264)</li> <li> firefox: thunderbird: Memory safety bugs (CVE-2025-5268)</li> <li> firefox: thunderbird: Script element events leaked cross-origin resource status (CVE-2025-5266)</li> <li> firefox: thunderbird: Error handling for script execution was incorrectly isolated from web content (CVE-2025-5263)</li> <li> firefox: thunderbird: Memory safety bug (CVE-2025-5269)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:8598?
The severity of RHSA-2025:8598 is classified as Important.
How do I fix RHSA-2025:8598?
To fix RHSA-2025:8598, update the Thunderbird package to version 128.11.0-1.el9_0.
What vulnerabilities are addressed by RHSA-2025:8598?
RHSA-2025:8598 addresses out-of-bounds access vulnerabilities when resolving Promise objects, identified as CVE-2025-4918.
Which systems are affected by RHSA-2025:8598?
RHSA-2025:8598 affects various versions of Red Hat Enterprise Linux, including Power LE, ARM 64, x86_64, and IBM z Systems.
Is there a risk of exploitation with RHSA-2025:8598?
Yes, the vulnerabilities in RHSA-2025:8598 could potentially be exploited to execute arbitrary code, posing a significant security risk.