{"id":"CLSA-2026-1779579653","summary":"thunderbird: Fix of 4 CVEs","details":"- CVE-2024-0742: assertion failure in nsPresContext::UserInputEventsAllowed\n  (Document::SetIsInitialDocument sticky-bit)\n- CVE-2025-2830: path traversal via malformed attachment filename in multipart\n  message (directory guard in MimePart._fetchAttachment + mimedrft.cpp)\n- CVE-2025-3909: predictable tempfile path enables JavaScript execution from\n  attachment opened in file:/// context (per-PID tempdir, 0o700)\n- CVE-2025-3932: tracking links in attachments bypass remote-content blocking\n  (scheme allowlist + FeedMsg http(s) carve-out in AttachmentInfo.isEmpty)","modified":"2026-05-27T11:17:53.348381634Z","published":"2026-05-25T07:35:52Z","upstream":["CVE-2024-0742","CVE-2025-2830","CVE-2025-3909","CVE-2025-3932"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/almalinux9.2esu/CLSA-2026-1779579653.html"}],"affected":[{"package":{"name":"thunderbird","ecosystem":"TuxCare:AlmaLinux:9.2","purl":"pkg:rpm/tuxcare/thunderbird?distro=almalinux-9.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"115.4.1-1.el9_2.alma.tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2026-1779579653.json"}}],"schema_version":"1.7.5"}