CVE-2025-3523

Publication date 15 April 2025

Last updated 13 May 2026


Ubuntu priority

Cvss 3 Severity Score

6.4 · Medium

Score breakdown

Description

When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering over any attachment. Although the correct link is used on click, the misleading hover text could trick users into downloading content from untrusted sources. This vulnerability was fixed in Thunderbird 137.0.2 and Thunderbird 128.9.2.

Status

Package Ubuntu Release Status
thunderbird 25.04 plucky
Not affected
24.10 oracular
Not affected
24.04 LTS noble
Not affected
22.04 LTS jammy
Fixed 1:128.12.0+build1-0ubuntu0.22.04.1
20.04 LTS focal Not in release

Severity score breakdown

CVSS version: CVSS v3.0

Base score 6.4 · Medium

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L


Access our resources on patching vulnerabilities