Bug 2336182 (CVE-2025-0237) - CVE-2025-0237 firefox: thunderbird: WebChannel APIs susceptible to confused deputy attack
Summary: CVE-2025-0237 firefox: thunderbird: WebChannel APIs susceptible to confused d...
Keywords:
Status: NEW
Alias: CVE-2025-0237
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-01-07 17:02 UTC by OSIDB Bzimport
Modified: 2025-04-06 18:55 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2025:0080 0 None None None 2025-01-08 11:32:41 UTC
Red Hat Product Errata RHSA-2025:0132 0 None None None 2025-01-09 06:31:00 UTC
Red Hat Product Errata RHSA-2025:0133 0 None None None 2025-01-09 06:23:50 UTC
Red Hat Product Errata RHSA-2025:0134 0 None None None 2025-01-09 06:29:28 UTC
Red Hat Product Errata RHSA-2025:0135 0 None None None 2025-01-09 06:29:21 UTC
Red Hat Product Errata RHSA-2025:0136 0 None None None 2025-01-09 06:32:38 UTC
Red Hat Product Errata RHSA-2025:0137 0 None None None 2025-01-09 06:45:58 UTC
Red Hat Product Errata RHSA-2025:0138 0 None None None 2025-01-09 06:45:39 UTC
Red Hat Product Errata RHSA-2025:0144 0 None None None 2025-01-09 07:31:52 UTC
Red Hat Product Errata RHSA-2025:0162 0 None None None 2025-01-09 11:08:21 UTC

Description OSIDB Bzimport 2025-01-07 17:02:20 UTC
The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.

Comment 1 errata-xmlrpc 2025-01-08 11:32:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:0080 https://access.redhat.com/errata/RHSA-2025:0080

Comment 2 errata-xmlrpc 2025-01-09 06:23:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2025:0133 https://access.redhat.com/errata/RHSA-2025:0133

Comment 3 errata-xmlrpc 2025-01-09 06:29:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:0135 https://access.redhat.com/errata/RHSA-2025:0135

Comment 4 errata-xmlrpc 2025-01-09 06:29:27 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.4 Telecommunications Update Service

Via RHSA-2025:0134 https://access.redhat.com/errata/RHSA-2025:0134

Comment 5 errata-xmlrpc 2025-01-09 06:30:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2025:0132 https://access.redhat.com/errata/RHSA-2025:0132

Comment 6 errata-xmlrpc 2025-01-09 06:32:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2025:0136 https://access.redhat.com/errata/RHSA-2025:0136

Comment 7 errata-xmlrpc 2025-01-09 06:45:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Extended Update Support

Via RHSA-2025:0138 https://access.redhat.com/errata/RHSA-2025:0138

Comment 8 errata-xmlrpc 2025-01-09 06:45:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Extended Update Support

Via RHSA-2025:0137 https://access.redhat.com/errata/RHSA-2025:0137

Comment 9 errata-xmlrpc 2025-01-09 07:31:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:0144 https://access.redhat.com/errata/RHSA-2025:0144

Comment 10 errata-xmlrpc 2025-01-09 11:08:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:0162 https://access.redhat.com/errata/RHSA-2025:0162


Note You need to log in before you can comment on or make changes to this bug.