-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 31 Jul 2020 19:35:57 +0200 Source: thunderbird Architecture: source Version: 1:78.1.0-1 Distribution: experimental Urgency: medium Maintainer: Carsten Schoenert <c.schoenert@t-online.de> Changed-By: Carsten Schoenert <c.schoenert@t-online.de> Changes: thunderbird (1:78.1.0-1) experimental; urgency=medium . * [c4099cd] New upstream version 78.1.0 Fixed CVE issues in upstream version 78.1.0 (MFSA 2020-33): CVE-2020-15652: Potential leak of redirect targets when loading scripts in a worker CVE-2020-6514: WebRTC data channel leaks internal address to peer CVE-2020-15655: Extension APIs could be used to bypass Same-Origin Policy CVE-2020-15653: Bypassing iframe sandbox when allowing popups CVE-2020-6463: Use-after-free in ANGLE gl::Texture::onUnbindAsSamplerTexture CVE-2020-15656: Type confusion for special arguments in IonMonkey CVE-2020-15658: Overriding file type when saving to disk CVE-2020-15657: DLL hijacking due to incorrect loading path CVE-2020-15654: Custom cursor can overlay user interface CVE-2020-15659: Memory safety bugs fixed in Thunderbird 78.1 Checksums-Sha1: d5e492849da11fdada86d716541b775a4d59c12f 8101 thunderbird_78.1.0-1.dsc 9fda69d6cf58c9c561ec9e7b64296d4d4fdcc75c 12179448 thunderbird_78.1.0.orig-thunderbird-l10n.tar.xz 9128b79e5bb8f416337d07452af2fbd03a6a494a 373626372 thunderbird_78.1.0.orig.tar.xz 45606d0cdbdbcf4a050f9ac06f6a172d8e0e6b4e 543260 thunderbird_78.1.0-1.debian.tar.xz 9f537080352c42eee7b63fbedd1c01b1441def30 35333 thunderbird_78.1.0-1_amd64.buildinfo Checksums-Sha256: 630e2be8e65b3d299c0688eecbdfb054ba683003dfa23edaf4ca5544c7dcefd4 8101 thunderbird_78.1.0-1.dsc 0c788b72d9616dcf646bb0390b8ee1e9f0fd8d4f2df048216ebf868500a268d9 12179448 thunderbird_78.1.0.orig-thunderbird-l10n.tar.xz 212d7e274cdfa4a307db93915c7ee82e7a4c47e6d4508876ebf80aa79fe68e8f 373626372 thunderbird_78.1.0.orig.tar.xz a2681b6a72689380759b347a85a63852e93968a063a8328c8968c304a5aade4d 543260 thunderbird_78.1.0-1.debian.tar.xz 09066ca1def555b36129be4600eef2da01ea7eb6552a1e622ba5a43e17d7c378 35333 thunderbird_78.1.0-1_amd64.buildinfo Files: 87ed1107c3ef62a2e86b3229f048979b 8101 mail optional thunderbird_78.1.0-1.dsc 96f482bf4613b4a455eacc922ae8f5a7 12179448 mail optional thunderbird_78.1.0.orig-thunderbird-l10n.tar.xz 9ece105bc8adbbf7d7c55e7b6d933902 373626372 mail optional thunderbird_78.1.0.orig.tar.xz 600c387e05bf95efb57da2612455ed90 543260 mail optional thunderbird_78.1.0-1.debian.tar.xz c811685d558de8eda16fb8f1bf038ff2 35333 mail optional thunderbird_78.1.0-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIyBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAl8keckACgkQgwFgFCUd HbCmYQ/3SWq6yuUl4cn5C5n/hKVkREn5deScvU7iGl+Ec0BlVluzMYG08Cwr3R4H si0QeGtc517bhzAb5Ydyq7Jzr/0d8AwLq7EiHvLSAHfgEbl7DnAikeoxfUV5/OaY 1doOX3C/+0Mb7K/iByfA4HDVl8G0axi6autScw6fFtjnXRwuJv+XrIwR0iJDt7gS rhP74FAfn2MzyWcrG9OpKp7T6Joviy2WE+jKyaUTpBHiKVRn6dbpFu/jigbXUmGG 4YTXV9s0UwISHRIkHeU9WSqCFHbwW/GozLQQRP7+u7oNbG3fKiAim+LcR0ACY/p2 wFv3gcRlL4xWU+sDiUqrIIZDQW0MV9BJmn2bZ1ll4uoid5J7NcVghjLxlUfHXf6z DbKMiyCfr5rdD2BH7Y3RWQIXgiUGV32uSPDIdbMiBNChBfi2SOBVc40vPkhrhZnG upDTCfuW/WCgj6Ss1iwnJPm+0GAoqE4QIAlIAFajhvFjhSAJ+6a4feFAh5N+sV9Z B5Ct+zGfbP78dUwcRjlFvAe5+ST4F9XAzdsX8Q8UhVERD7tEDMx8rArmNGi2ab3c G8HUuII9n76lpon6vKsD7HALPQTXD7m7VVWZvG6JfkRpLmc/6yGkySoQwxISoiDd vZTK/qQy1aB6Q5YjIgjbv7nMj7U1gSV9W+a8Yg4MGfmkyLQ6PQ== =vPpD -----END PGP SIGNATURE-----