Debian 10705 Published by

Debian has released security updates for Thunderbird, which address multiple vulnerabilities that could lead to arbitrary code execution. The affected versions are 1:140.5.0esr-1deb11u1 for Debian GNU/Linux 11 (Bullseye) LTS and 1:140.5.0esr-1deb12u1 and 1:140.5.0esr-1~deb13u1 for Debian GNU/Linux 12 (Bookworm) and 13 (Trixie). Users are recommended to upgrade their Thunderbird packages to fix these security issues.

[DLA 4372-1] thunderbird security update
[DSA 6059-1] thunderbird security update




[SECURITY] [DLA 4372-1] thunderbird security update


- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4372-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Emilio Pozuelo Monfort
November 16, 2025 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : thunderbird
Version : 1:140.5.0esr-1~deb11u1
CVE ID : CVE-2025-13012 CVE-2025-13013 CVE-2025-13014 CVE-2025-13015
CVE-2025-13016 CVE-2025-13017 CVE-2025-13018 CVE-2025-13019
CVE-2025-13020

Multiple security issues were discovered in Thunderbird, which could
potentially result in the execution of arbitrary code or bypass of the
same-origin policy.

For Debian 11 bullseye, these problems have been fixed in version
1:140.5.0esr-1~deb11u1.

We recommend that you upgrade your thunderbird packages.

For the detailed security status of thunderbird please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/thunderbird

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



[SECURITY] [DSA 6059-1] thunderbird security update


- -------------------------------------------------------------------------
Debian Security Advisory DSA-6059-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
November 16, 2025 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : thunderbird
CVE ID : CVE-2025-13012 CVE-2025-13013 CVE-2025-13014
CVE-2025-13015 CVE-2025-13016 CVE-2025-13017
CVE-2025-13018 CVE-2025-13019 CVE-2025-13020

Multiple security issues were discovered in Thunderbird, which could
result in the execution of arbitrary code.

For the oldstable distribution (bookworm), these problems have been fixed
in version 1:140.5.0esr-1~deb12u1.

For the stable distribution (trixie), these problems have been fixed in
version 1:140.5.0esr-1~deb13u1.

We recommend that you upgrade your thunderbird packages.

For the detailed security status of thunderbird please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/thunderbird

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/