-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 31 Aug 2023 17:15:52 +0200 Source: thunderbird Architecture: source Version: 1:102.15.0-1~deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: Carsten Schoenert <c.schoenert@t-online.de> Changed-By: Christoph Goehre <chris@sigxcpu.org> Changes: thunderbird (1:102.15.0-1~deb12u1) bookworm-security; urgency=medium . * [6c701df] New upstream version 102.15.0 Fixed CVE issues in upstream version 102.15 (MFSA 2023-35): CVE-2023-4573: Memory corruption in IPC CanvasTranslator CVE-2023-4574: Memory corruption in IPC ColorPickerShownCallback CVE-2023-4575: Memory corruption in IPC FilePickerShownCallback CVE-2023-4576: Integer Overflow in RecordedSourceSurfaceCreation CVE-2023-4581: XLL file extensions were downloadable without warnings CVE-2023-4584: Memory safety bugs fixed in Firefox 117, Firefox ESR 102.15, Firefox ESR 115.2, Thunderbird 102.15, and Thunderbird 115.2 Checksums-Sha1: d4b46ca6ee1604a6fa8952ea85650bf635cc14bb 8538 thunderbird_102.15.0-1~deb12u1.dsc 0d93f26f80c9de374ff4fbe7f1ec3729c9161563 12643888 thunderbird_102.15.0.orig-thunderbird-l10n.tar.xz 6b9794c32f5b451e83a31e5b1a7e73f870b99c3e 521162908 thunderbird_102.15.0.orig.tar.xz a4fe3c78fca84aa3eb09019e5dd8b21fb4ba75ec 548588 thunderbird_102.15.0-1~deb12u1.debian.tar.xz Checksums-Sha256: f20bc8b87ab6ccdb3330fe247b1e98c7e42e4c95d018ed7676906fcf996140d1 8538 thunderbird_102.15.0-1~deb12u1.dsc 25dd23f3fec74e908c282e3c188163ee08f0c992705d701be79d2aabe235922c 12643888 thunderbird_102.15.0.orig-thunderbird-l10n.tar.xz a5ecb8ac9e545d4b343abdeefe8b28d3130bd699884f3903cb5239ac9317f094 521162908 thunderbird_102.15.0.orig.tar.xz fc7b026fb0b8399f8b9658434fd70f6183157cb213755678573f5d5ee7407f4e 548588 thunderbird_102.15.0-1~deb12u1.debian.tar.xz Files: 3e0337de34e6d6b197023ee64524e513 8538 mail optional thunderbird_102.15.0-1~deb12u1.dsc 4daad48ac8390dbaa0e5e81f13a2052d 12643888 mail optional thunderbird_102.15.0.orig-thunderbird-l10n.tar.xz 60b9d76fe1222c0ce4f0f62bedfc4ded 521162908 mail optional thunderbird_102.15.0.orig.tar.xz 39122c03b43defc30af1468b9de90fda 548588 mail optional thunderbird_102.15.0-1~deb12u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEi5SBnCVVcKN0tizNJuPIdadEIO8FAmTwy38ACgkQJuPIdadE IO8aGBAAq/xkJQ6PRVKPN9e9+cxN69RUXuFqtsJLqY4y5GNwWunOFAE9TMyOeA+T yT2zvxov7Axf6sFse/LccM+KHcKfr9DbAQevfgrTLCSmoowRuH1V2x0DQQeKDl+L oIBrP0tg2wUmLKRFPNRIvI/9R6WshHziLEJBVpcUYpLtwnaes37tz+rTihh8PSSm LWQJAzS1NdCtjsW1L90DgKWeYH+IGHD6LB7N2t8cfsgfLG7OFxYVihwosHLZ51cG kdxKwMLiqObp9FmFUu+rNhyfzdO9wOKXHtA6IK8Xuh+CjSRnTIw273yoWN0HJM1M EANxjiH51+ptk2L4cXmM19h9EkZwcFlpUmJbXRcmI8D53pCBDkzv9az8hUfJOLLX 2oBOi3NCS1DxMvMVsMhgY2gsP4Woz1ULuTOnvsEZxzT1xgC3isVa16bxPDdGYjgd RIgu1rC7NFi7qPA5CBtVJpZKVcMm/CjatvDbK44rjr7ZAqGoRL+BcRRLgO3+TXuc bVSa+u+OD9dGZDjDeqFjBoMUVxQG1gLPJydqJdEO1z6i32RPLtZX8QNRBJml4oqq NUHZdXzbM65s15oaQ18aZy77SjYG/h1E1qBIB9aan+gSBe91RCWaWH2hz5O7WJz6 6Tb5lFOoDYskFPDCXwfXjEpIsw72Ld64swk8Wrr6Dzmdv7xJY2w= =B7Em -----END PGP SIGNATURE-----