| Name | CVE-2025-0239 |
| Description | When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DLA-4011-1, DLA-4012-1, DSA-5839-1, DSA-5841-1 |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| firefox (PTS) | sid | 150.0-1 | fixed |
| firefox-esr (PTS) | bullseye | 115.14.0esr-1~deb11u1 | vulnerable |
| bullseye (security) | 140.10.0esr-1~deb11u1 | fixed | |
| bookworm | 128.14.0esr-1~deb12u1 | fixed | |
| bookworm (security) | 140.10.0esr-1~deb12u1 | fixed | |
| trixie | 140.8.0esr-1~deb13u1 | fixed | |
| trixie (security) | 140.10.0esr-1~deb13u1 | fixed | |
| forky | 140.9.1esr-1 | fixed | |
| sid | 140.10.0esr-1 | fixed | |
| thunderbird (PTS) | bullseye | 1:115.12.0-1~deb11u1 | vulnerable |
| bullseye (security) | 1:140.10.0esr-1~deb11u1 | fixed | |
| bookworm | 1:140.6.0esr-1~deb12u1 | fixed | |
| bookworm (security) | 1:140.10.0esr-1~deb12u1 | fixed | |
| trixie | 1:140.8.0esr-1~deb13u1 | fixed | |
| trixie (security) | 1:140.10.0esr-1~deb13u1 | fixed | |
| forky | 1:140.9.1esr-1 | fixed | |
| sid | 1:140.10.0esr-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| firefox | source | (unstable) | 134.0-1 | |||
| firefox-esr | source | bullseye | 128.6.0esr-1~deb11u3 | DLA-4011-1 | ||
| firefox-esr | source | bookworm | 128.6.0esr-1~deb12u1 | DSA-5839-1 | ||
| firefox-esr | source | (unstable) | 128.6.0esr-1 | |||
| thunderbird | source | bullseye | 1:128.6.0esr-1~deb11u1 | DLA-4012-1 | ||
| thunderbird | source | bookworm | 1:128.6.0esr-1~deb12u1 | DSA-5841-1 | ||
| thunderbird | source | (unstable) | 1:128.6.0esr-1 |
https://www.mozilla.org/en-US/security/advisories/mfsa2025-01/#CVE-2025-0239
https://www.mozilla.org/en-US/security/advisories/mfsa2025-02/#CVE-2025-0239
https://www.mozilla.org/en-US/security/advisories/mfsa2025-05/#CVE-2025-0239