Vulnerability CVE-2025-1942: Information
Description
When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string This vulnerability affects Firefox < 136 and Thunderbird < 136.
Fixed packages
Package name | Branch | Fixed in version | Version from repository | Errata ID | Task # | State |
---|---|---|---|---|---|---|
firefox | sisyphus | 136.0-alt1 | 136.0.2-alt1 | ALT-PU-2025-4104-2 | 376916 | Fixed |
firefox | sisyphus_loongarch64 | 136.0.1-alt0.port | 136.0.1-alt0.port | ALT-PU-2025-4467-1 | - | Fixed |
firefox | p11 | 136.0.2-alt1 | 135.0.1-alt1 | ALT-PU-2025-4567-1 | 378599 | Testing |
thunderbird | sisyphus | 136.0-alt1 | 136.0-alt1 | ALT-PU-2025-4378-2 | 378178 | Fixed |
thunderbird | sisyphus_riscv64 | 136.0-alt1 | 136.0-alt1 | ALT-PU-2025-4408-1 | - | Fixed |
thunderbird | sisyphus_loongarch64 | 136.0-alt1 | 136.0-alt1 | ALT-PU-2025-4395-1 | - | Fixed |