PT-2025-1008 · Mozilla+10 · Thunderbird+11

Andrew Mccreight

+1

·

Published

2025-01-07

·

Updated

2025-07-22

·

CVE-2025-0242

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Firefox versions prior to 134 Firefox ESR versions prior to 128.6 Firefox ESR versions prior to 115.19 Thunderbird versions prior to 134 Thunderbird versions prior to 128.6
Description: The issue is related to memory safety bugs that could potentially be exploited to run arbitrary code. These bugs have shown evidence of memory corruption. The vulnerability can be exploited by a remote attacker using a specially crafted website, potentially allowing them to execute arbitrary code.
Recommendations: For Firefox versions prior to 134, update to version 134 or later. For Firefox ESR versions prior to 128.6, update to version 128.6 or later. For Firefox ESR versions prior to 115.19, update to version 115.19 or later. For Thunderbird versions prior to 134, update to version 134 or later. For Thunderbird versions prior to 128.6, update to version 128.6 or later.

Fix

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:0080
ALSA-2025:0144
ALSA-2025:0147
ALSA-2025:0281
ALT-PU-2025-1154
ALT-PU-2025-1681
ALT-PU-2025-1972
ALT-PU-2025-1984
ALT-PU-2025-2027
ALT-PU-2025-2230
BDU:2025-00156
CESA-2025_0144
CESA-2025_0281
CVE-2025-0242
DLA-4011-1
DLA-4012-1
DSA-5839-1
DSA-5841-1
INFSA-2025_0080
INFSA-2025_0144
INFSA-2025_0147
INFSA-2025_0281
MGASA-2025-0009
MGASA-2025-0010
OESA-2025-1085
OESA-2025-1086
OESA-2025-1835
OPENSUSE-SU-2025:14619-1
OPENSUSE-SU-2025:14630-1
OPENSUSE-SU-2025:14648-1
OPENSUSE-SU-2025_0059-1
OPENSUSE-SU-2025_0080-1
RHSA-2025:0080
RHSA-2025:0132
RHSA-2025:0133
RHSA-2025:0134
RHSA-2025:0135
RHSA-2025:0136
RHSA-2025:0137
RHSA-2025:0138
RHSA-2025:0144
RHSA-2025:0147
RHSA-2025:0162
RHSA-2025:0165
RHSA-2025:0166
RHSA-2025:0167
RHSA-2025:0275
RHSA-2025:0281
RHSA-2025:0284
RHSA-2025:0286
RHSA-2025:0287
RHSA-2025_0080
RHSA-2025_0144
RHSA-2025_0147
RHSA-2025_0281
RLSA-2025:0144
RLSA-2025:0281
SUSE-SU-2025:0056-1
SUSE-SU-2025:0059-1
SUSE-SU-2025:0080-1
USN-7191-1
USN-7663-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Firefox
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Thunderbird
Ubuntu