-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 01 Aug 2023 19:19:27 +0200 Source: thunderbird Architecture: source Version: 1:115.1.0-1 Distribution: unstable Urgency: medium Maintainer: Carsten Schoenert <c.schoenert@t-online.de> Changed-By: Carsten Schoenert <c.schoenert@t-online.de> Changes: thunderbird (1:115.1.0-1) unstable; urgency=medium . * [8c11865] d/gbp.conf: Adjust upstream branch to new ESR cycle * [fb76340] New upstream version 115.1.0 Fixed CVE issues in upstream version 115.1 (MFSA 2023-33): CVE-2023-4045: Offscreen Canvas could have bypassed cross-origin restrictions CVE-2023-4046: Incorrect value used during WASM compilation CVE-2023-4047: Potential permissions request bypass via clickjacking CVE-2023-4048: Crash in DOMParser due to out-of-memory conditions CVE-2023-4049: Fix potential race conditions when releasing platform objects CVE-2023-4050: Stack buffer overflow in StorageManager CVE-2023-4055: Cookie jar overflow caused unexpected cookie jar state CVE-2023-4056: Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1, Firefox ESR 102.14, Thunderbird 115.1, and Thunderbird 102.14 CVE-2023-4057: Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1 * [b562827] Rebuild patch queue from patch-queue branch Removed patches (included upstream): fixes/Bug-1840931-More-properly-handle-files-4GB-in-elfhack.-r-.patch fixes/Bug-1842933-Use-NEON_FLAGS-instead-of-VPX_ASFLAGS-for-lib.patch porting-mips/Bug-1841197-Undefine-the-mips-builtin-macro-on-mips-in-sk.patch porting-mips64el/Bug-1841201-Work-around-tail-call-optimization-not-happen.patch porting-ppc64el/Work-around-bz-1775202-to-fix-FTBFS-on-ppc64el.patch Checksums-Sha1: 67c8e786590c27d8179fde170b3ff8d544eae78d 8492 thunderbird_115.1.0-1.dsc 4b80a27dfbbe073379bce7ac74c04921a9b392af 12605908 thunderbird_115.1.0.orig-thunderbird-l10n.tar.xz 8753cef2ab8b4db4be31791e1515e911217c977e 556096840 thunderbird_115.1.0.orig.tar.xz b24db0f707fcc4ca47d12cc8e24b401a0079fcca 540984 thunderbird_115.1.0-1.debian.tar.xz f0e50200fa6bd02a00f8b2938d4bb0d0c291f75f 39527 thunderbird_115.1.0-1_amd64.buildinfo Checksums-Sha256: 4c60b88e0fe492bfc661c3f566506605e5a989d67bbb0946762f64a26c70b49e 8492 thunderbird_115.1.0-1.dsc f73235ff994a17f467bfe3a6812ba27097852740f970f2421ad64fed72a3ea99 12605908 thunderbird_115.1.0.orig-thunderbird-l10n.tar.xz 3a740733311ed7cab5f34790202c7d30b88e2a0345e28adb705add1d12e76577 556096840 thunderbird_115.1.0.orig.tar.xz 60832e95ba3e49dbda9909bab3b6c1e8ab47dec053fad5500494bb3a096e5546 540984 thunderbird_115.1.0-1.debian.tar.xz 175eaf55720ec51e2ccd4340079bd3d8e14edf830e99955557312749ed875c2c 39527 thunderbird_115.1.0-1_amd64.buildinfo Files: 4746e7ad1b19cfe3989bac02e0a66b7c 8492 mail optional thunderbird_115.1.0-1.dsc 9918cf7896c00e5bb1c83917ece01633 12605908 mail optional thunderbird_115.1.0.orig-thunderbird-l10n.tar.xz f751a46e00994fa585babb750448e5f2 556096840 mail optional thunderbird_115.1.0.orig.tar.xz 9fae5c3b97ffc8157bbf0c15126bb2c9 540984 mail optional thunderbird_115.1.0-1.debian.tar.xz 96a93d0e149021be7aad375efbb6c428 39527 mail optional thunderbird_115.1.0-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmTL6WQACgkQgwFgFCUd HbCQRxAAhMmi0TWkHiYcBESDUWW6f6r/vLbxflAKGflBUKPTwtKKhFrKy2FB04rJ C43gULgRqwqa0kR/h9eN6ntbvepo1zMV2z4tBu7yy2S19flqk9iNkq3Ju21cg/qw qdxlwJcvnsruscAUSJCzLE07alBjwjj5FHn1225d1mR07KCcRZJZRhq+54nRDPMQ IIUQR9QuiUAa9SMpQ9u3J5xtcc0WjXtFWKoDrCG8GtERKJPSfhueXJRpcekgq66O V/VTyebW7+JQImRVE7nJhRfJ0xLAWnNBLEFnMxJRcd1Wrcp9Ch/p0bA9c/oRRUdx OwJpdAmpCtTvB4TYOva3/bo7+py7DnKPCzTtXkLzw82I7trpXh1TAXwzM4ZkLV6n CP7306JTxK/IK2dIQjKZqmsLn5AaI4O2bSnVlUcGPFYZbId5dxhgYr3a9xFKIRKq DEmozW99JrRBR8YwnLlV4yuxQR9gq5qCPNZuyck4DsBWFZeDYUCZsbOE29ZiFifv ILeNJcMlIWEfXabilVUHVExH61XiUif9w+JJ3kaOkBKxM1XCkZ4QSn3YR0jjo0/0 8Zp43Jx/YniTV+eSIM5tR4dAMv/HnBkZJH8ZWImTfx+4AiKf34NVoBi7Zp5EOctK D0BtD/RNqrQQ4INPyOs9LuPT8BYLq7JG3Ivxr9/OT85N4y3DqfI= =N33s -----END PGP SIGNATURE-----