Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 953890 (MFSA2025-25, MFSA2025-26, MFSA2025-27) - [Tracker] Mozilla Foundation Security Advisory for April 15, 2025
Summary: [Tracker] Mozilla Foundation Security Advisory for April 15, 2025
Status: CONFIRMED
Alias: MFSA2025-25, MFSA2025-26, MFSA2025-27
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Security
URL: https://www.mozilla.org/en-US/securit...
Whiteboard:
Keywords: Tracker
Depends on: CVE-2025-3608 CVE-2025-2830, CVE-2025-3523
Blocks:
  Show dependency tree
 
Reported: 2025-04-15 19:20 UTC by Christopher Fore
Modified: 2025-04-15 19:22 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Christopher Fore 2025-04-15 19:20:17 UTC
CVE-2025-2830:

By crafting a malformed file name for an attachment in a multipart
message, an attacker can trick Thunderbird into including a
directory listing of /tmp when the message is forwarded or edited
as a new message. This vulnerability could allow attackers to
disclose sensitive information from the victim's system. This
vulnerability is not limited to Linux; similar behavior has been
observed on Windows as well.


CVE-2025-3523:

When an email contains multiple attachments with external links
via the X-Mozilla-External-Attachment-URL header, only the last
link is shown when hovering over any attachment. Although the
correct link is used on click, the misleading hover text could
trick users into downloading content from untrusted sources.


Firefox 137.0.2: https://www.mozilla.org/en-US/security/advisories/mfsa2025-25/
Thunderbird 137.0.2: https://www.mozilla.org/en-US/security/advisories/mfsa2025-26/
Thunderbird 128.9.2: https://www.mozilla.org/en-US/security/advisories/mfsa2025-27/
Comment 1 Christopher Fore 2025-04-15 19:22:29 UTC
Disregard the two CVEs here, they do not affect Firefox. Sorry!