CVE-2025-3932

Description

It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accessed the link. The configuration to block remote content did not prevent that. Thunderbird has been fixed to no longer allow access to web pages listed in the X-Mozilla-External-Attachment-URL header of an email. This vulnerability was fixed in Thunderbird 128.10.1 and Thunderbird 138.0.1.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.281

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2025-3875,CVE-2025-3877,CVE-2025-3909,CVE-2025-3932 are fixed in Mozilla Thunderbird (138.0.1)Windows
Vulnerabilities CVE-2025-3875,CVE-2025-3877,CVE-2025-3909,CVE-2025-3932 are fixed in Mozilla Thunderbird (x64) (138.0.1)Windows
Vulnerabilities CVE-2025-3875,CVE-2025-3877,CVE-2025-3909,CVE-2025-3932 are fixed in Mozilla Thunderbird 128 (x64) (128.10.1)Windows
Vulnerabilities CVE-2025-3875,CVE-2025-3877,CVE-2025-3909,CVE-2025-3932 are fixed in Mozilla Thunderbird 128 (128.10.1)Windows
Vulnerabilities CVE-2025-3875,CVE-2025-3909,CVE-2025-3932 are affected in Mozilla Thunderbird 138.0.0Windows
Vulnerabilities CVE-2025-3909,CVE-2025-3932 are affected in Mozilla Thunderbird 128.10.0Windows
Vulnerabilities CVE-2025-3875,CVE-2025-3909,CVE-2025-3932 are fixed in Mozilla Thunderbird For Mac 128.10.1Mac
Vulnerabilities CVE-2025-3875,CVE-2025-3909,CVE-2025-3932 are fixed in Mozilla Thunderbird For Mac 138.0.1Mac
thunderbird security update(DSA-5921-1) thunderbird-l10n-en-gb_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-es-ar_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-es-es_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-es-mx_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-et_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-eu_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-fi_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird_128.10.1esr-1~deb12u1_amd64.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-fy-nl_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-ga-ie_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-gd_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-gl_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-he_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-hr_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-hsb_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-hu_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-fr_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird_128.10.1esr-1~deb12u1_i386.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-af_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-all_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-ar_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-ast_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-be_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-bg_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-en-ca_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-ca_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-cak_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-cs_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-cy_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-da_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-de_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-dsb_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-el_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-br_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-pt-pt_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-rm_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-ro_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-ru_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-sk_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-sl_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-sq_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-hy-am_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-sv-se_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-th_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-tr_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-uk_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-uz_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-vi_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-zh-cn_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-zh-tw_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-sr_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-id_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-is_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-it_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-ja_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-ka_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-kab_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-kk_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-pt-br_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-lt_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-lv_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-ms_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-nb-no_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-nl_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-nn-no_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-pa-in_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-pl_128.10.1esr-1~deb12u1_all.debLinux
thunderbird security update(DSA-5921-1) thunderbird-l10n-ko_128.10.1esr-1~deb12u1_all.debLinux
Thunderbird update (ELSA-2025-8203) thunderbird-128.10.1-1.0.1.el9_6.x86_64.rpmLinux
(RHSA-2025:8203)Important: security update thunderbird-128.10.1-1.el9_6.x86_64.rpmLinux
thunderbird Security Update (ALAS-2025-2859) thunderbird-128.10.1-1.amzn2.0.1.x86_64.rpmLinux
(RHSA-2025:8196)Important: security update thunderbird-128.10.1-1.el10_0.x86_64.rpmLinux
Important: thunderbird security update thunderbird-128.11.0-1.el8_10.alma.1.x86_64.rpmLinux
Thunderbird update (ELSA-2025-8756) thunderbird-128.11.0-1.0.1.el8_10.x86_64.rpmLinux
(RHSA-2025:8756)Important: security update thunderbird-128.11.0-1.el8_10.x86_64.rpmLinux
Mozilla Open Source mail and newsgroup client (USN-7663-1) USN-7663-1 thunderbird_128.12.0+build1-0ubuntu0.22.04.1_amd64.debLinux

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-347988Mozilla Thunderbird (138.0.1)
PATCH-347989Mozilla Thunderbird (x64) (138.0.1)
PATCH-611807Mozilla Thunderbird For Mac (142.0)
PATCH-611807Mozilla Thunderbird For Mac (142.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234