-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 28 Aug 2022 19:49:01 +0200 Source: thunderbird Architecture: source Version: 1:91.13.0-1~deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: Carsten Schoenert <c.schoenert@t-online.de> Changed-By: Carsten Schoenert <c.schoenert@t-online.de> Changes: thunderbird (1:91.13.0-1~deb11u1) bullseye-security; urgency=medium . * [06edfee] New upstream version 91.13.0 Fixed CVE issues in upstream version 91.13 (MFSA 2022-37): CVE-2022-38472: Address bar spoofing via XSLT error handling CVE-2022-38473: Cross-origin XSLT Documents would have inherited the parent's permissions CVE-2022-38478: Memory safety bugs fixed in Thunderbird 102.2, and Thunderbird 91.13 Checksums-Sha1: 96986503c21e6ecf7133017af736db55dbad9214 8437 thunderbird_91.13.0-1~deb11u1.dsc c4bca161e4e29b168a16fe22d686899d32a1f8f3 12305260 thunderbird_91.13.0.orig-thunderbird-l10n.tar.xz f817be24aeafe813dc04e793649eeede16806c38 422053248 thunderbird_91.13.0.orig.tar.xz 9bba032807e5f121243a6f73f67f72648010dd1a 546784 thunderbird_91.13.0-1~deb11u1.debian.tar.xz Checksums-Sha256: 30d11ba4d3fe1552716f12ab82efe96e1f66ca74e4310922cf5e06c46f9be20e 8437 thunderbird_91.13.0-1~deb11u1.dsc d6a0b8ebe95a7bb4bf640d2a92e1037ba88842233723ae58d68da54a6413ffbb 12305260 thunderbird_91.13.0.orig-thunderbird-l10n.tar.xz e612201575106fc4744dcf055a9a548b8a9d5140a7df9b619d87cefbc70ba2bc 422053248 thunderbird_91.13.0.orig.tar.xz b3d50bab9972993f5fe42228151e449c7e5b19e8c20f20b3a85179e51bae9353 546784 thunderbird_91.13.0-1~deb11u1.debian.tar.xz Files: 16d26325b151da864be080c099f7e518 8437 mail optional thunderbird_91.13.0-1~deb11u1.dsc edf9fd65e14375281be5286a74c559e5 12305260 mail optional thunderbird_91.13.0.orig-thunderbird-l10n.tar.xz 05745e0b61ea2c6624d46b662324ada7 422053248 mail optional thunderbird_91.13.0.orig.tar.xz 4a64ea763b54a380212d9393e34bf2ff 546784 mail optional thunderbird_91.13.0-1~deb11u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmMMWeMACgkQgwFgFCUd HbCMCA/9FUk7wTc5U4+HRqtP2/HakP6N+hA948jRWHOFS5K9XTaT1ul1MewQSLt1 3+9w3zDiRYUM+56QazB1WBKdHzQwGD5kenSfWuEFtAXsjGMKIJDctJIx1msN4kYN 9POJPAY9m72tx0vua4+3X/OHlsW0EyCMPc7EdY8BqFtGEn9MmGTOxZ/Q84P8HfIc SrFvdVpgESUp3N8ezUeEbCnd6/lj3KeN31eY2slVPbj42V8aBi/lV53xnaxJ4kKP oA0ykq8Vq7/e3P2qe2rNMimXZunzfLeoKI00dW1StPlMNbuC8kH+6D0Gtj/fY7/U aWze3YE/kij077k416mTLQU+VT2002wVuP/8mj+c7cvAZ9onDHKetKCyELU4lu4D En6EUlCeL6s286QWXejDv/ni1ZCTODELe3F+0lraDK+lHssLLHdfAlm6lDi1nbkq 8p+Vm+nOiBU47Au/Z+IbHIulG6+oXmbkcQ8CBBMY1Wgu1C4zaP59pQnpGLy6NXyR aUdKM4/sp5GFk678Gw6ej1xUz2W8BmnM1Xx4JfMaPM5Nuc2m3jJRVh6+llKdslG4 +8TYsiiFPA1YemdoTTY0nvShudOGqyVRxnliAE7O1YZ3ra19kYXxPu05ihDFdEWG ucjDCjeqIoNqxMkHCm8VtJhsjhJziI+TlxeYum1PE7KouZ8eHV4= =2UxG -----END PGP SIGNATURE-----