-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5921-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 16, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : thunderbird CVE ID : CVE-2025-3875 CVE-2025-3877 CVE-2025-3909 CVE-2025-3932 Multiple security issues were discovered in Thunderbird, which could result in spoofing of From: mail headers, execution of JavaScript or information disclosure. For the stable distribution (bookworm), these problems have been fixed in version 1:128.10.1esr-1~deb12u1. We recommend that you upgrade your thunderbird packages. For the detailed security status of thunderbird please refer to its security tracker page at: https://security-tracker.debian.org/tracker/thunderbird Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmgnj+0ACgkQEMKTtsN8 TjaeFBAAh3eWJ9Lnkevk8a486b1Iz5t+L4384QjQwklPMRmJRHdiodBvNl8G91ZJ 8COQBLMC8N3xbgoSIFmCVlJMENADGNjHM1NOiLNmcy1lF1Ek7QjVmKC/K9EEpljj g+3HbkBRhDHG967O9oumIGOWbyzIfJPlwKBQtdjBLiSVN3EwdV/FGpDz5YZbM+BW nhhtwJ2v/zoq/5m+1McJrqxvkvdScf2MOILsIzSPmL/+I5t2/Kdec7sKsPylOlxb Lptlu/80OmCPfiNFEl7Zee5s9UqYSPW/4ykJLY6TRcZKlaV7loNCW7OtR1ycIQfy NI0AyFFxAd3dCc/wfp1xcT9BwdlyCpm7tu6FMft24+GJxEgN0x/E9paO7YZOvly4 sUXKCfvBEUK7wpsJkBtXNwLOm9TDF+0gMpb8sTO3VHLlWKYRNWQ4VL7WB1Y2xHol dYx+CeZkNXOhbgGdl2NJuwZc+A1wbNNwVfX5c9WvGaljbLNYM6stFEwc8M03TeHV Zc9kH2LTXhbdfoBLhUCNzOt+iZrYxm6vy7dvb50v2xWphVOr5NgDSFwf7S3I9OvK ULnso7a7WUVrWV69151tJ1clxAQgHa1Cj8ENMtbgfHOQG+iUVqh+1jls5Ivns9SI whNEFC4EqErBsewsqor2Bve1zsyDeoywZCxByFHaDUHldwkxFkw= =LU0K -----END PGP SIGNATURE-----