VDB

DEBIAN-CVE-2025-0239

DEBIAN-CVE-2025-0239 PUBLISHED CVSS 4 MEDIUM

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

Risk Scores

CVSS 3.1
4
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected Products

VendorProductVersions
Debian:11firefox-esr91.9.1esr-1~deb11u1, *, *
Debian:14thunderbird0, 0
Debian:13firefox-esr0, 0
Debian:13thunderbird0, 0
Debian:14firefox-esr0, 0
Debian:11thunderbird1:128.5.2esr-1, 1:78.12.0-1, 1:78.13.0-1
Debian:12firefox-esr*, 0, 102.11.0esr-1
Debian:12thunderbird1:115.13.0-1, 1:115.12.0-1~deb12u1, 1:115.12.0-1~deb11u1

Exploit Intelligence

Timeline

  • Jan 7, 2025 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›