Release date:
2026-05-25 07:35:52 UTC
Description:
- CVE-2024-0742: assertion failure in nsPresContext::UserInputEventsAllowed
(Document::SetIsInitialDocument sticky-bit)
- CVE-2025-2830: path traversal via malformed attachment filename in multipart
message (directory guard in MimePart._fetchAttachment + mimedrft.cpp)
- CVE-2025-3909: predictable tempfile path enables JavaScript execution from
attachment opened in file:/// context (per-PID tempdir, 0o700)
- CVE-2025-3932: tracking links in attachments bypass remote-content blocking
(scheme allowlist + FeedMsg http(s) carve-out in AttachmentInfo.isEmpty)
Updated packages:
-
thunderbird-115.4.1-1.el9_2.alma.tuxcare.els3.x86_64.rpm
sha:23698637255e25a43ea9201816498ee8a5c13ea63e609cbfd3c9dded82b895d9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.