-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 15 Mar 2022 17:54:46 +0100 Source: thunderbird Architecture: source Version: 1:91.7.0-1 Distribution: unstable Urgency: medium Maintainer: Carsten Schoenert <c.schoenert@t-online.de> Changed-By: Carsten Schoenert <c.schoenert@t-online.de> Changes: thunderbird (1:91.7.0-1) unstable; urgency=medium . * [952f6d0] New upstream version 91.7.0 Fixed CVE issues in upstream version 91.7 (MFSA 2022-12): CVE-2022-26383: Browser window spoof using fullscreen mode CVE-2022-26384: iframe allow-scripts sandbox bypass CVE-2022-26387: Time-of-check time-of-use bug when verifying add-on signatures CVE-2022-26381: Use-after-free in text reflows CVE-2022-26386: Temporary files downloaded to /tmp and accessible by other local users Checksums-Sha1: 1f70012f2d5f3eab14a34f4f73b7fbc909884df1 8430 thunderbird_91.7.0-1.dsc 08fbc9d571502cdc74bccf73b8ba9477a8f68e61 12175916 thunderbird_91.7.0.orig-thunderbird-l10n.tar.xz b5d066c3a1c78417564effe1068757f3cb7e6713 427489528 thunderbird_91.7.0.orig.tar.xz 40923fc9fe494329435c7fbeb9fb70b1ce3e8938 543872 thunderbird_91.7.0-1.debian.tar.xz 67fee1b86e18d9907855387360872961be077d09 36590 thunderbird_91.7.0-1_amd64.buildinfo Checksums-Sha256: 9989b17d0f3e1add4dcd591a046e5ae9c4cbe80866aa06644bba001141aa1b31 8430 thunderbird_91.7.0-1.dsc 7319725b21bf99bc8896296d0d4e4db52c44af9bf662e0a21b989eb96f7eabdd 12175916 thunderbird_91.7.0.orig-thunderbird-l10n.tar.xz abb1e61f4d3eecc9753a558e68ad27ed4a0d0f3ea05e1f32f741ecfb71b6a877 427489528 thunderbird_91.7.0.orig.tar.xz 4f0b771f697e9943324f59007751b3cc94f673578f1c0a81324c39fe777bde30 543872 thunderbird_91.7.0-1.debian.tar.xz c23ff2f28f93d4898cfa60d540ff7679c60e0ac65b5b606610152be0030b2063 36590 thunderbird_91.7.0-1_amd64.buildinfo Files: a12c583806a1ab4fae447f3cf5bfd69d 8430 mail optional thunderbird_91.7.0-1.dsc 0675af2198957f7710e185231ebf172f 12175916 mail optional thunderbird_91.7.0.orig-thunderbird-l10n.tar.xz bc897e805ba2bd1b3dc97d08a226c55b 427489528 mail optional thunderbird_91.7.0.orig.tar.xz 082e64f813efc74a5c233cffa457dfa5 543872 mail optional thunderbird_91.7.0-1.debian.tar.xz 8745519fba7ddb06905b619e383c4a22 36590 mail optional thunderbird_91.7.0-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmIw+m4ACgkQgwFgFCUd HbBHkhAAiILstox5pSjUeBaQgJHqxzANYX/WxSWLaWpY1KHSU46eOHsUsnv8nXxB LoG21evDwyS5CDx02QZQhl8o3dhRm8r27+O6JO0STLOXLoImMq+4soENFOqVP6gB zHAv5+oS1eAEXUVuv7+p8RrchCAbXUS4zRhYvBuJxuav0O1gxyuOIIz2RDO0grM1 Agqv4PxYCFHOTDb4uWp3n55HIVYwa57UufsPpN4m03I5WzsdHTVcZtwcdz9ua2xu BjVSGR1O0DZmIbIjo0ksxw4Y/37GfIp6NnimrKPGfq2Qqivkrcw9BunKVm9eM7iO zDZ9gAfdJoMq6upM0EWJuMoVH53iHDJZNXyyRzGlJ/jkvtur1t5XD19Otu4NuNSM BBP8KfC8skqoPJYN4GTL2hatjljmvjas2wO2lhlA0g8DvhjA/k0E1wihVgVUkUs+ z7kquEmihiqGWnOF1v7QCLgVD1Qu0QAc8DwgNejOR5hJ0x/MFDwJfOK7/l91UJa7 zLcET+QRYSOuCSjUlyfNDoJoPuQwnAUwCnNaibBVY4B99Z4oMkiU7ky9g6lwmmGi +zQILBM6/x2DN8e2pHamL+m8AV4EPmbTSgS1t7VqKfuxD0zUJxfZMi10N1vSPZLi 3G99qt80671sVHxiRN7Z5z6+Lj9V71hP0Myi6eiUmht/crMWgyQ= =O121 -----END PGP SIGNATURE-----