Vulnerability Details
Basic Information
| Title | RHEL 9 : thunderbird (RHSA-2025:4229) |
|---|---|
| Type | nessus |
| Published | 2025-04-28T00:00:00 |
| Last Seen | 2025-04-28T11:26:26 |
| CVSS Score | 6.4 (MEDIUM) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | HIGH |
| Privileges Required | NONE |
| User Interaction | REQUIRED |
| Scope | UNCHANGED |
| Confidentiality Impact | LOW |
| Integrity Impact | HIGH |
| Availability Impact | LOW |
CVE Information
| CVE IDs | CVE-2025-2830, CVE-2025-3522, CVE-2025-3523 |
|---|---|
| CWE | |
| Bulletin Family | scanner |
Description
Mozilla Thunderbird is a standalone mail and newsgroup client.
Security Fix(es):
* thunderbird: User Interface (UI) Misrepresentation of attachment URL (CVE-2025-3523)
* thunderbird: Information Disclosure of /tmp directory listing (CVE-2025-2830)
* thunderbird: Leak of hashed Window credentials via crafted attachment URL (CVE-2025-3522)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application’s self-reported version number.
File data redhat-RHSA-2025-4229.nasl
Impact Assessment
| Base Score | 6.4 |
|---|---|
| Severity | MEDIUM |