Input validation error in Mozilla Thunderbird - CVE-2025-1015

 

Input validation error in Mozilla Thunderbird - CVE-2025-1015

Published: February 4, 2025 / Updated: February 7, 2025


Vulnerability identifier: #VU103615
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-1015
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient validation of user-supplied input when handling the Address Book URI fields. A remote attacker create and export an address book containing a malicious payload in a field, trick the victim into clicking on the link after importing the address book and a web page inside Thunderbird.


Affected software

Mozilla Thunderbird
Debian Linux
SUSE Linux Enterprise Workstation Extension 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Slackware Linux
SUSE Package Hub 15
openSUSE Leap
Ubuntu
openEuler
Oracle Solaris
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
mozilla-thunderbird
thunderbird (Debian package)
thunderbird (Red Hat package)
thunderbird
MozillaThunderbird-translations-other
MozillaThunderbird-debugsource
MozillaThunderbird-translations-common
MozillaThunderbird-debuginfo
MozillaThunderbird
thunderbird-debuginfo
thunderbird-debugsource
thunderbird-librnp-rnp
thunderbird-wayland
thunderbird (Ubuntu package)

How to mitigate CVE-2025-1015

Install updates from vendor's website.

Mozilla Thunderbird - update to 128.7.0
Oracle Solaris - addressed in versions 11.3 ESU 36.34, 11.4 SRU 80
mozilla-thunderbird - update to 128.7.0esr
thunderbird (Debian package) - update to 1:128.7.0esr-1~deb12u1
thunderbird (Red Hat package) - addressed in versions 128.7.0-1.el8_2, 128.7.0-1.el8_6, 128.7.0-1.el8_8, 128.7.0-1.el8_10, 128.7.0-1.el9_0, 128.7.0-1.el9_2, 128.7.0-1.el9_4, 128.7.0-1.el9_5
thunderbird - update to 128.7.0-1.0.1
MozillaThunderbird-translations-other - update to 128.7.0-150200.8.200.1
MozillaThunderbird-debugsource - update to 128.7.0-150200.8.200.1
MozillaThunderbird-translations-common - update to 128.7.0-150200.8.200.1
MozillaThunderbird-debuginfo - update to 128.7.0-150200.8.200.1
MozillaThunderbird - update to 128.7.0-150200.8.200.1
thunderbird - update to 128.11.1-1
thunderbird-debuginfo - update to 128.11.1-1
thunderbird-debugsource - update to 128.11.1-1
thunderbird-librnp-rnp - update to 128.11.1-1
thunderbird-wayland - update to 128.11.1-1
thunderbird (Ubuntu package) - update to 1:128.12.0+build1-0ubuntu0.22.04.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins