Bug 2336181 (CVE-2025-0242) - CVE-2025-0242 firefox: thunderbird: Memory safety bugs fixed in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6
Summary: CVE-2025-0242 firefox: thunderbird: Memory safety bugs fixed in Firefox 134, ...
Keywords:
Status: NEW
Alias: CVE-2025-0242
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-01-07 17:02 UTC by OSIDB Bzimport
Modified: 2025-04-06 18:55 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2025:0080 0 None None None 2025-01-08 11:32:39 UTC
Red Hat Product Errata RHSA-2025:0132 0 None None None 2025-01-09 06:30:58 UTC
Red Hat Product Errata RHSA-2025:0133 0 None None None 2025-01-09 06:23:50 UTC
Red Hat Product Errata RHSA-2025:0134 0 None None None 2025-01-09 06:29:28 UTC
Red Hat Product Errata RHSA-2025:0135 0 None None None 2025-01-09 06:29:17 UTC
Red Hat Product Errata RHSA-2025:0136 0 None None None 2025-01-09 06:32:42 UTC
Red Hat Product Errata RHSA-2025:0137 0 None None None 2025-01-09 06:45:57 UTC
Red Hat Product Errata RHSA-2025:0138 0 None None None 2025-01-09 06:45:39 UTC
Red Hat Product Errata RHSA-2025:0144 0 None None None 2025-01-09 07:31:52 UTC
Red Hat Product Errata RHSA-2025:0147 0 None None None 2025-01-09 07:26:50 UTC
Red Hat Product Errata RHSA-2025:0162 0 None None None 2025-01-09 11:08:21 UTC
Red Hat Product Errata RHSA-2025:0165 0 None None None 2025-01-09 11:54:05 UTC
Red Hat Product Errata RHSA-2025:0166 0 None None None 2025-01-09 12:08:07 UTC
Red Hat Product Errata RHSA-2025:0167 0 None None None 2025-01-09 12:21:51 UTC
Red Hat Product Errata RHSA-2025:0275 0 None None None 2025-01-13 10:47:11 UTC
Red Hat Product Errata RHSA-2025:0281 0 None None None 2025-01-13 10:47:40 UTC
Red Hat Product Errata RHSA-2025:0284 0 None None None 2025-01-13 11:21:08 UTC
Red Hat Product Errata RHSA-2025:0286 0 None None None 2025-01-13 11:46:47 UTC
Red Hat Product Errata RHSA-2025:0287 0 None None None 2025-01-13 11:29:41 UTC

Description OSIDB Bzimport 2025-01-07 17:02:16 UTC
Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, and Firefox ESR < 115.19.

Comment 1 errata-xmlrpc 2025-01-08 11:32:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:0080 https://access.redhat.com/errata/RHSA-2025:0080

Comment 2 errata-xmlrpc 2025-01-09 06:23:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2025:0133 https://access.redhat.com/errata/RHSA-2025:0133

Comment 3 errata-xmlrpc 2025-01-09 06:29:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:0135 https://access.redhat.com/errata/RHSA-2025:0135

Comment 4 errata-xmlrpc 2025-01-09 06:29:27 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.4 Telecommunications Update Service

Via RHSA-2025:0134 https://access.redhat.com/errata/RHSA-2025:0134

Comment 5 errata-xmlrpc 2025-01-09 06:30:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2025:0132 https://access.redhat.com/errata/RHSA-2025:0132

Comment 6 errata-xmlrpc 2025-01-09 06:32:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2025:0136 https://access.redhat.com/errata/RHSA-2025:0136

Comment 7 errata-xmlrpc 2025-01-09 06:45:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Extended Update Support

Via RHSA-2025:0138 https://access.redhat.com/errata/RHSA-2025:0138

Comment 8 errata-xmlrpc 2025-01-09 06:45:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Extended Update Support

Via RHSA-2025:0137 https://access.redhat.com/errata/RHSA-2025:0137

Comment 9 errata-xmlrpc 2025-01-09 07:26:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:0147 https://access.redhat.com/errata/RHSA-2025:0147

Comment 10 errata-xmlrpc 2025-01-09 07:31:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:0144 https://access.redhat.com/errata/RHSA-2025:0144

Comment 11 errata-xmlrpc 2025-01-09 11:08:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:0162 https://access.redhat.com/errata/RHSA-2025:0162

Comment 12 errata-xmlrpc 2025-01-09 11:54:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:0165 https://access.redhat.com/errata/RHSA-2025:0165

Comment 13 errata-xmlrpc 2025-01-09 12:08:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:0166 https://access.redhat.com/errata/RHSA-2025:0166

Comment 14 errata-xmlrpc 2025-01-09 12:21:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Extended Update Support

Via RHSA-2025:0167 https://access.redhat.com/errata/RHSA-2025:0167

Comment 15 errata-xmlrpc 2025-01-13 10:47:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2025:0275 https://access.redhat.com/errata/RHSA-2025:0275

Comment 16 errata-xmlrpc 2025-01-13 10:47:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:0281 https://access.redhat.com/errata/RHSA-2025:0281

Comment 17 errata-xmlrpc 2025-01-13 11:21:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Extended Update Support

Via RHSA-2025:0284 https://access.redhat.com/errata/RHSA-2025:0284

Comment 18 errata-xmlrpc 2025-01-13 11:29:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.4 Telecommunications Update Service

Via RHSA-2025:0287 https://access.redhat.com/errata/RHSA-2025:0287

Comment 19 errata-xmlrpc 2025-01-13 11:46:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2025:0286 https://access.redhat.com/errata/RHSA-2025:0286


Note You need to log in before you can comment on or make changes to this bug.