SB2025061334 - SUSE update for MozillaThunderbird 



SB2025061334 - SUSE update for MozillaThunderbird

Published: June 13, 2025

Security Bulletin ID SB2025061334
Severity
High
Patch available
YES
Number of vulnerabilities 8
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 38% Medium 50% Low 13%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 8 secuirty vulnerabilities.


1) Double free (CVE-ID: CVE-2025-5262)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the vpx_codec_enc_init_multi() function in libvpx encoder for WebRTC. A remote attacker can trick the victim into visiting a specially crafted website, trigger a double free error and execute arbitrary code on the target system.


2) Improper error handling (CVE-ID: CVE-2025-5263)

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to error handling for script execution is not correctly isolated from the web content. A remote attacker can trick the victim into opening a specially crafted website and obtain certain information cross-origin.



3) Input validation error (CVE-ID: CVE-2025-5264)

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input within the "Copy as cURL" feature. A remote attacker can trick the victim into copying a specially crafted URL, trick the victim into using this command and execute arbitrary commands on the system.


4) Input validation error (CVE-ID: CVE-2025-5265)

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input within the "Copy as cURL" feature. A remote attacker can trick the victim into copying a specially crafted URL, trick the victim into using this command and execute arbitrary commands on the system.

The vulnerability affects Windows installations only.


5) Information disclosure (CVE-ID: CVE-2025-5266)

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to script elements loading cross-origin resources generated load and error events, which leaked information. A remote attacker can gain access to sensitive information.


6) Insufficient UI Warning of Dangerous Operations (CVE-ID: CVE-2025-5267)

The vulnerability allows a remote attacker to perform clickjacking attacks.

The vulnerability exists due to an error in the UI that can lead to information disclosure. A remote attacker can perform a clickjacking attack and trick a user into leaking saved payment card details to a malicious page.


7) Buffer overflow (CVE-ID: CVE-2025-5268)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content. A remote attacker can create a specially crafted website, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


8) Buffer overflow (CVE-ID: CVE-2025-5269)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing HTML content. A remote attacker can create a specially crafted website, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install update from vendor's website.