-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 16 Mar 2020 20:01:29 +0100 Source: thunderbird Architecture: source Version: 1:68.6.0-1 Distribution: unstable Urgency: medium Maintainer: Carsten Schoenert <c.schoenert@t-online.de> Changed-By: Carsten Schoenert <c.schoenert@t-online.de> Changes: thunderbird (1:68.6.0-1) unstable; urgency=medium . * [5709774] New upstream version 68.6.0 Fixed CVE issues in upstream version 68.6.0 (MFSA 2020-10): CVE-2019-20503: Out of bounds reads in sctp_load_addresses_from_init CVE-2020-6805: Use-after-free when removing data about origins CVE-2020-6806: BodyStream::OnInputStreamReady was missing protections against state confusion CVE-2020-6807: Use-after-free in cubeb during stream destruction CVE-2020-6811: Devtools' 'Copy as cURL' feature did not fully escape website-controlled data, potentially leading to command injection CVE-2020-6812: The names of AirPods with personally identifiable information were exposed to websites with camera or microphone permission CVE-2020-6814: Memory safety bugs fixed in Thunderbird 68.6 Checksums-Sha1: 6b6a7a1a9940efe8e18efd878d2c82b335a04507 8274 thunderbird_68.6.0-1.dsc 4c3a2848972393cc8610df2fb2f0c56dbfe6c241 1046832 thunderbird_68.6.0.orig-lightning-l10n.tar.xz 271aa0fab810eb73731829e41e9aceacfb546817 9836428 thunderbird_68.6.0.orig-thunderbird-l10n.tar.xz 0310ea2e655f9befa15773a1a1286af9eefb62c2 356981864 thunderbird_68.6.0.orig.tar.xz dd4546d014290bc16f3bde62792f105ab5a1c217 546492 thunderbird_68.6.0-1.debian.tar.xz 25298642d62146d491dca3f7045e6b64574582df 35562 thunderbird_68.6.0-1_amd64.buildinfo Checksums-Sha256: 9bec679ef0a6201168df6c1fc1cb6f42249c4455110ec3d1312326dc3102e806 8274 thunderbird_68.6.0-1.dsc bffe30fd372d1660b2e9fd9f64f1faa23bef9b708d0c22c22e5db43cfe99eb7e 1046832 thunderbird_68.6.0.orig-lightning-l10n.tar.xz 2b97cee9f8651f6b5ac6386b225c16758b59b4934003fa6f6c59af7bab437a0b 9836428 thunderbird_68.6.0.orig-thunderbird-l10n.tar.xz ece4422ade1838b3c2a543803d71f2890041806c0eb1f6801cf76ee65afa5b85 356981864 thunderbird_68.6.0.orig.tar.xz 211da736c2088dedff50f955fef5530251e9981d75447b2bb5a1a96708ffacd0 546492 thunderbird_68.6.0-1.debian.tar.xz fa61265d6003ee3736f49e5ef69da58c820cf7667ddfba6f405c938b02a5bd24 35562 thunderbird_68.6.0-1_amd64.buildinfo Files: 524c402df3000c5dc8b5112b8bcba2f5 8274 mail optional thunderbird_68.6.0-1.dsc 829df3669f19d85e1f452a2d909ae0b0 1046832 mail optional thunderbird_68.6.0.orig-lightning-l10n.tar.xz cf90395270b772c9f40a422b06cc13e9 9836428 mail optional thunderbird_68.6.0.orig-thunderbird-l10n.tar.xz 8c06ab50b3d9517a362b07b5dff350a0 356981864 mail optional thunderbird_68.6.0.orig.tar.xz 480f4880904871f005ad8a62b3662cb5 546492 mail optional thunderbird_68.6.0-1.debian.tar.xz cf99cd27ddbb8d69e0558b35a9bd7e35 35562 mail optional thunderbird_68.6.0-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAl5v8YEACgkQgwFgFCUd HbAPUA//b2WuysGkFIGtR4QY6pFJiQNcL9YwCIGteam7YJRPQlOYy3+Knxx6oD0E jJ4akHAjZ4864Fij8hP82/Ayb9+GktG/brxwGKCaejY20dQHqbxtd4Mp1XzIAyeY 2ByXgl2MZmQw6kU5uQMI7GlGFTB1BCw7lj9AT8LrNdr2JHRKNI/NXEJ+7G+HraZQ lTKLTpO+FtUuRxFrb0Q+agbQIlnFOjIgEa5NW6visDsvbIMucYM1JxW4ZTdEUhcO aT5tRXz2a32CWWrnGxNA5M/eSscDKj4dRsvkgslL87+HaQVdgdTLoZufilphTU5e EXrg/3VJ345tJ7ObUUVi0CKhVeGMdnpDP96vvpy+3qeWKo7Ix/IpUuuVX4obRUVI 2fZuYZLngmWd9oyGXNKgMMNahAf8ygm7O0xTsZDQOstKyyTkn6Ed/A4vZSQjT5PH UE88h8/DijVKCq/QRDgjpb2fnpc11+QVzflTMH9UoVXBd0GMvBjX8u16cb2NNvjg tCEyKwV3fl9s+RQudXaxQiR5vI1x4hUuHmasbmZHoC1xaZefj0Yn6Sf6EffQ2OoY b83dH/RHATDhBKtH8A/FWTgyMfVsT9nnLxg13Bdk9Jl1sb803uUeTcE65xskcjix 846Q3QycxlnIDhxrneTNqdCY6D/dE0hgKrBdlQd2naNiVpDJqoA= =xUhF -----END PGP SIGNATURE-----