-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 29 Jan 2021 20:45:49 +0100 Source: thunderbird Architecture: source Version: 1:78.7.0-1 Distribution: unstable Urgency: medium Maintainer: Carsten Schoenert <c.schoenert@t-online.de> Changed-By: Carsten Schoenert <c.schoenert@t-online.de> Changes: thunderbird (1:78.7.0-1) unstable; urgency=medium . * [8751354] New upstream version 78.7.0 Fixed CVE issues in upstream version 78.7 (MFSA 2021-05): CVE-2021-23953: Cross-origin information leakage via redirected PDF requests CVE-2021-23954: Type confusion when using logical assignment operators in JavaScript switch statements CVE-2020-15685: IMAP Response Injection when using STARTTLS CVE-2020-26976: HTTPS pages could have been intercepted by a registered service worker when they should not have been CVE-2021-23960: Use-after-poison for incorrectly redeclared JavaScript variables during GC CVE-2021-23964: Memory safety bugs fixed in Thunderbird 78.7 * [4b0c0a7] rebuild patch queue from patch-queue branch removed patch (included upstream): porting-mips/Bug-1642265-MIPS64-Add-branchTestSymbol-and-fallibleUnbox.patch Checksums-Sha1: f318f503c38246692261481f802ff48e11d66e3c 8151 thunderbird_78.7.0-1.dsc 784dca21d0767c9368d4bf676d91a6419431ddbd 11809524 thunderbird_78.7.0.orig-thunderbird-l10n.tar.xz 3dcf8b21d89e3c99b7f3838a28745edf360a1ab4 372479988 thunderbird_78.7.0.orig.tar.xz ac95d4199f0bc5c09ce8e28eaec2b6b6f72d8adf 706096 thunderbird_78.7.0-1.debian.tar.xz 4436c3dca50fef11dd3ce817be9784807e70323d 35593 thunderbird_78.7.0-1_amd64.buildinfo Checksums-Sha256: d1959dc9dc987b5a927613523e0e1dea0e42c41522503bced83cccd47adf884e 8151 thunderbird_78.7.0-1.dsc 2242a5759774178f5634a5c0ba716a2658d38284149ede5aa1ced2204abc5f4c 11809524 thunderbird_78.7.0.orig-thunderbird-l10n.tar.xz c3d3e7e6b7d2b10615f4feeb14759caf28d2ab1b87cc6fdf3bd0f1b04c26b39f 372479988 thunderbird_78.7.0.orig.tar.xz 041643d2141ae786f49272e8a2d981511f00fc8b725abc969036200bb62b2422 706096 thunderbird_78.7.0-1.debian.tar.xz 54fcc07b0baf147b340bad6a4ab52b1ee6b3a556c33b2a94e68b3272af46f9c3 35593 thunderbird_78.7.0-1_amd64.buildinfo Files: 668e5f248320c92d4a9f9279efc26dc4 8151 mail optional thunderbird_78.7.0-1.dsc 461b5933347eeec26be97bbb3a971851 11809524 mail optional thunderbird_78.7.0.orig-thunderbird-l10n.tar.xz fda198723555d22277c834ad36661267 372479988 mail optional thunderbird_78.7.0.orig.tar.xz d3b50997999117986d2f472af5501c69 706096 mail optional thunderbird_78.7.0-1.debian.tar.xz 802c044d0c0e7f2c0f98e3d322e7e150 35593 mail optional thunderbird_78.7.0-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmAUfMIACgkQgwFgFCUd HbAHoA/+ORWLCJTAOjTSFvVYtRWm7bknJBMqF8j364Uu+Qv4aI2zRiJE0ZjX+/q2 uRfiihdOym9Wljb8aR9MtWmeHc9OQdq/ST9m/hRUt/pmh3SxwHoD6YDyMV/qmDxl l972ci5UmbkVhyFR701smJnEpgbuX21EAgttuejZqkbuwqcPcMgVSGq4zaFmAOmm 7ahwwUO2deVbtbnpTXClcQt1hjCUA1+2s9+eDixXwg40O1tAnEDFBsyySa5spP+v Ei6h3cyRKXd3KhY7/RkvdGqgsDJI9QAF95tvxZDdm4xKRt6eTEtD66NQdB26jqsf P6je8uK+kTv2zUqg6f0DWjAWQNTqNeq+uUDSfRlOw9rguL3KTPpWQ+D9sk9Aix7X 1NEqIy8IYwxSY8v6jNm3W/xvIAf3ZRO5YplTismviSwv9YLncpFp8ARwPEowt6Xx naQH6lBE/cTJCu/73Tow8iQ07oaahLmycoPj/tgX5Tg7SsOh3ePiPnlPa/mK3Sp8 wOishvq5dFogKNzO7S6nhNZUSA1CHL9F+/eGwKMdB/QkL839OpHH7A4HPJtyHbT+ tATU6Ni7nanq9dBnaHcmZIrS0SKjjzV7JARVAoUBXODpsjbURuTYyfPYQ9LsmsKC SzDe94IlBCEIZxLphDeeha0FjPXfP5Ig4DCL7pr3/FjYcI1UHuw= =CrSa -----END PGP SIGNATURE-----