-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 20 Apr 2024 19:35:18 +0200 Source: thunderbird Architecture: source Version: 1:115.10.1-1 Distribution: unstable Urgency: medium Maintainer: Carsten Schoenert <c.schoenert@t-online.de> Changed-By: Carsten Schoenert <c.schoenert@t-online.de> Closes: 1069337 Changes: thunderbird (1:115.10.1-1) unstable; urgency=medium . [ William Desportes ] * [d0cbb66] Fix a typo in the wrapper file . [ Carsten Schoenert ] * [47d140b] New upstream version 115.10.1 Fixed CVE issues in upstream version 115.10 (MFSA 2024-20): CVE-2024-3852: GetBoundName in the JIT returned the wrong object CVE-2024-3854: Out-of-bounds-read after mis-optimized switch statement CVE-2024-3857: Incorrect JITting of arguments led to use-after-free during garbage collection CVE-2024-2609: Permission prompt input delay could expire when not in focus CVE-2024-3859: Integer-overflow led to out-of-bounds-read in the OpenType sanitizer CVE-2024-3861: Potential use-after-free due to AlignedBuffer self-move CVE-2024-3302: Denial of Service using HTTP/2 CONTINUATION frames CVE-2024-3864: Memory safety bug fixed in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10 * [5612f7b] d/control: Move libotr5 to libotr5t64 for bin:thunderbird (Closes: #1069337) * [195482a] d/mozconfig.default: Use internal shipped librnp version The Debian package has a RC bug for longer time which would prevent the migration of the thunderbird package to testing. * [cd4de72] d/control: Drop dependencies on librnp{0,-dev} * [761eb83] d/thunderbird.install: Install local built rnp tools * [ce212a8] d/control: Increase Standards-Version to 4.7.0 No further changes needed. Checksums-Sha1: 4e47bbec144f005d5ca9f7c1edad6e38efcb8fad 8449 thunderbird_115.10.1-1.dsc 10c1831b356931e4c3fc6c7f417906d2628f9cb1 13012840 thunderbird_115.10.1.orig-thunderbird-l10n.tar.xz 1d19a8ceee2335dd5fe15c1f49bbbeea9d02e11a 554681316 thunderbird_115.10.1.orig.tar.xz 372538c0acb1dfce30373f8146627d63559f9704 545028 thunderbird_115.10.1-1.debian.tar.xz b27399680659c4f63b65db5e118a231c033d38e1 40807 thunderbird_115.10.1-1_amd64.buildinfo Checksums-Sha256: 09ec419b1c3793756eff247d016e30c42c3c0192b9bd6d4103ffdb7b5c9b23c3 8449 thunderbird_115.10.1-1.dsc f29941558f252eec961b57dcfa3adab58b87d64a90162364783c799f21779dd9 13012840 thunderbird_115.10.1.orig-thunderbird-l10n.tar.xz 5c1d09b1f89a82ce2ec2c4ea8f86f04b0c00183d8b492936d7452e4b4a991ba4 554681316 thunderbird_115.10.1.orig.tar.xz c6b74481d13836c098e7ef648b4e68b80aaa07c56145bf87f6093508863cb6b0 545028 thunderbird_115.10.1-1.debian.tar.xz 15b3e9b4d45edda01ec4944f7e0714c28ef216d7fd3522b861f88afd861f1746 40807 thunderbird_115.10.1-1_amd64.buildinfo Files: b6582492fb90357ca4ee37442805f1c5 8449 mail optional thunderbird_115.10.1-1.dsc ae0a35287182fd7bba4c71e421db0282 13012840 mail optional thunderbird_115.10.1.orig-thunderbird-l10n.tar.xz cdb15941abd8ac62888af1f6b2f8230f 554681316 mail optional thunderbird_115.10.1.orig.tar.xz 417fdbc9bea96dc1bd2a6285adad209d 545028 mail optional thunderbird_115.10.1-1.debian.tar.xz bff837f18da212c27678125446c78b9e 40807 mail optional thunderbird_115.10.1-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmYkC3kACgkQgwFgFCUd HbDbixAArfxOMsZDcCuteA/1NNgD3OXQVk9eUrSoJfs8SnH7+mXU6ItT/5tUDMHu T9gpV7mXTTxEGvrRAHq+Pp0j5gQFcQpJ0ZjIZERBB7GbJ7q7aqwSrGwjFv0lub71 /GHeMa5fsatG/roFGfVrtf6LBLd4n9z1Ucn6oGFRBDmYtBIG8Mer07dfQKVGDPqw kuqUE1TcKm4jTZZr23rgwEVNtSDTn8ps4KVx7xftKN62I8nhoP2vjVB6umN7Sw5t mi92gAkk0BMOwdQx1mrQuk0fIEI0mntQA6wkyevCNmeFYqLg1z4NZWIkGSKkoZUi tSBsg2CPU7afDa7p5cs7QK8+WuYPZc42zw/XjYkyK6RUhZUN4yrsEuMmOt9t4+ti IChQtCHvediftezELawd4wbhN9GT9dZp03+aqyIjswD2tCq+lcHrmmmyMhQeZJ4i VXwXw/67MC4sHsSjFFuaLa/cAsy4Yf0bwLFPv+AsPH7NtG/hcod/gnBTleAhyOIj Y9R+Pbxrtq30L37gKIV9rONRcS3FY4ldck2+RnSE/rTG9Ep3ukwkhtNnR2kx2zZC 9lpeqxQ9ZUWRwHfuOM3TKSMFldjFN3LTblcS1ojfkRKRNtLnp+ApKv7IAPq1a4iX /A2nzOGj4ZUktWhR82BQp42MygnhEisSXrR7DjRpf0cSmIYc0fg= =syfc -----END PGP SIGNATURE-----