Debian Thunderbird Security Update: Check the Trixie Package

Debian has fixed multiple Thunderbird security flaws in its Trixie email-client package. The October 1 advisory, DSA-6536-1, names 1:140.17.0esr-1~deb13u1 as the fixed version for Debian 13. If you use that package, there is a short check to make before you assume the update is installed.

First find out which installation you have

Thunderbird’s name in the application menu does not tell you where it came from. A computer might run the Debian package, a Flatpak, or a copy unpacked from a download. Each takes a different route to an update.

For the packaged version, open a terminal and enter dpkg-query -W thunderbird. The result includes the package name and its installed version. If no Debian package is installed, investigate the source of your application instead of proceeding as though APT manages it.

What Debian has fixed

Debian’s security advisory covers multiple vulnerabilities and warns of possible code execution in some cases. That makes this an update to apply promptly. It does not mean the advisory has identified an attack on your own computer.

Use Debian’s security tracker to check the Trixie build. Comparing it with a Thunderbird release for Windows, or with a separate Linux download, will not establish whether the Debian package contains this fix.

Update through the existing repositories

Check the candidate before installing

  1. Enter sudo apt update and read any repository errors.
  2. Enter apt-cache policy thunderbird. Locate Installed and Candidate in the output.
  3. Compare those versions with the fixed Trixie package in the tracker.
  4. If the candidate is a newer build, enter sudo apt install --only-upgrade thunderbird.
  5. Review the proposed package changes, then confirm if they are what you expect.

The --only-upgrade option keeps this command focused on a package already present. If APT proposes unexpected removals, cancel and examine the package configuration rather than accepting the transaction just to get past the prompt.

A completed download is not the last step

Close Thunderbird and reopen it after installation. Until then, the application can still be running code it loaded before the update. Run dpkg-query -W thunderbird again to confirm what is installed.

A stale candidate calls for a repository check. Review the output of apt update and make sure the normal Debian security repository is enabled. Repeating the installation command cannot fix a failed refresh of the package lists.

Our earlier Debian kernel security update report concerns a separate package and a different restart requirement. Do not confuse having applied that fix with having updated Thunderbird. For this advisory, the package-version check and a fresh Thunderbird session are the useful completion points.

Visited 1 times, 2 visit(s) today

Leave a Reply

Your email address will not be published. Required fields are marked *