Debian 10694 Published by

Debian GNU/Linux has received two security updates: A Thunderbird update for both Debian 11 LTS and 12 and a PHP 7.4 update for Debian 11 LTS

[DSA 5966-1] thunderbird security update
[DLA 4253-1] thunderbird security update
[DLA 4254-1] php7.4 security update




[SECURITY] [DSA 5966-1] thunderbird security update


- -------------------------------------------------------------------------
Debian Security Advisory DSA-5966-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
July 27, 2025 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : thunderbird
CVE ID : CVE-2025-8027 CVE-2025-8028 CVE-2025-8029 CVE-2025-8030
CVE-2025-8031 CVE-2025-8032 CVE-2025-8033 CVE-2025-8034
CVE-2025-8035

Multiple security issues were discovered in Thunderbird, which could
result in the execution of arbitrary code.

For the stable distribution (bookworm), these problems have been fixed in
version 1:128.13.0esr-1~deb12u1.

We recommend that you upgrade your thunderbird packages.

For the detailed security status of thunderbird please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/thunderbird

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DLA 4253-1] thunderbird security update


- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4253-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Emilio Pozuelo Monfort
July 27, 2025 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : thunderbird
Version : 1:128.13.0esr-1~deb11u1
CVE ID : CVE-2025-8027 CVE-2025-8028 CVE-2025-8029 CVE-2025-8030
CVE-2025-8031 CVE-2025-8032 CVE-2025-8033 CVE-2025-8034
CVE-2025-8035

Multiple security issues were discovered in Thunderbird, which could
result in the execution of arbitrary code.

For Debian 11 bullseye, these problems have been fixed in version
1:128.13.0esr-1~deb11u1.

We recommend that you upgrade your thunderbird packages.

For the detailed security status of thunderbird please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/thunderbird

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



[SECURITY] [DLA 4254-1] php7.4 security update


-------------------------------------------------------------------------
Debian LTS Advisory DLA-4254-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Guilhem Moulin
July 27, 2025 https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package : php7.4
Version : 7.4.33-1+deb11u9
CVE ID : CVE-2025-1220 CVE-2025-1735 CVE-2025-6491

Multiple security issues were found in PHP, a widely-used open source
general purpose scripting language, which could result in server side
request forgery or denial of service.

CVE-2025-1220

Jihwan Kim discovered that fsockopen() lack validation that the
hostname supplied does not contain null characters, which may lead
to other functions like parse_url() to treat the hostname in an
incorrect way, thereby potentially causing Server Side Request
Forgery.

CVE-2025-1735

It was discovered that pgsql and pdo_pgsql escaping functions do not
check if the underlying quoting functions returned errors, which may
lead to crashes due to null pointer dereferences.

This issue is related to CVE-2025-1094 which was reported to
PostgreSQL.

CVE-2025-6491

Ahmed Lekssays discovered that SoapVar instances created with a
fully qualified name larger than 2G could lead to denial of service
due to null pointer dereference.

For Debian 11 bullseye, these problems have been fixed in version
7.4.33-1+deb11u9.

We recommend that you upgrade your php7.4 packages.

For the detailed security status of php7.4 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/php7.4

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS