-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 07 Aug 2024 18:44:31 +0200 Source: thunderbird Architecture: source Version: 1:115.14.0-1~deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: Carsten Schoenert <c.schoenert@t-online.de> Changed-By: Carsten Schoenert <c.schoenert@t-online.de> Changes: thunderbird (1:115.14.0-1~deb12u1) bookworm-security; urgency=medium . * [d608c75] New upstream version 115.14.0 Fixed CVE issues in upstream version 115.1 (MFSA 2024-38): CVE-2024-7519: Out of bounds memory access in graphics shared memory handling CVE-2024-7521: Incomplete WebAssembly exception handing CVE-2024-7522: Out of bounds read in editor component CVE-2024-7525: Missing permission check when creating a StreamFilter CVE-2024-7526: Uninitialized memory used by WebGL CVE-2024-7527: Use-after-free in JavaScript garbage collection CVE-2024-7529: Document content could partially obscure security prompts Checksums-Sha1: 623292fa48826ad48ce8b818dfb97596e0da61ae 8485 thunderbird_115.14.0-1~deb12u1.dsc a30a3426cce97128291627afa016c6fdd3ac93ca 13218020 thunderbird_115.14.0.orig-thunderbird-l10n.tar.xz cfe04af5896715774fc10e02c5bdf61d50f96b3a 558616920 thunderbird_115.14.0.orig.tar.xz 253e165b525511620e91aa3181c690fadac8a523 550192 thunderbird_115.14.0-1~deb12u1.debian.tar.xz Checksums-Sha256: 59c1842dfef269510a871949a02be59547814bce4ca927066fc1f8050d3caafc 8485 thunderbird_115.14.0-1~deb12u1.dsc f0a4c8556240b8a364e7460c50270f9fde30d8f95f60bd3de5355cd96bf1e577 13218020 thunderbird_115.14.0.orig-thunderbird-l10n.tar.xz aae76f1a172dd1db9a782b550e7e0e2b800251ede5df1813c1f53f887f0f9c2b 558616920 thunderbird_115.14.0.orig.tar.xz a12d184bf004337f3890dbaecda9bca791d3a4192846f85ca7222c5ed9dd7ed0 550192 thunderbird_115.14.0-1~deb12u1.debian.tar.xz Files: 2bc64ee8ad0a03f1164dce178cd2bc99 8485 mail optional thunderbird_115.14.0-1~deb12u1.dsc bba85e6903964cad884283563073da25 13218020 mail optional thunderbird_115.14.0.orig-thunderbird-l10n.tar.xz c59bfa8e2523e08e31f024a342548aa6 558616920 mail optional thunderbird_115.14.0.orig.tar.xz 02a1ff31afea4d1775ac7d7db2335407 550192 mail optional thunderbird_115.14.0-1~deb12u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAma0q4AACgkQgwFgFCUd HbAhdBAAq8xMWVg8cHT0ySq7FOpHFlIKkxsh7DcfdVPwch2baV+w0+kW2BEdhVNX S1+JtYxa/Kk7ZF+hV6m0DgtCwPU88AXI5A1gOZiYiQ90HNTBn5KoAtm9TgEWstUk NSIvZFzo0GjGLso9sW2Owmop6heTCIpTXrwGSqX/DjulpH2RzJ/WfWIkCMBYkZEp nbtj6FqryQZi5iJrn4V61FCjyWbNBILxlfRmRN2kGKg7hjIhnQPMzqZTbevsnm36 MZUQPTgBtDYYiecKyJO0iGaU9TuHW9U9K53b4ORxBYwrKTNNrx7tW9cqOB1ehVUx /cjeDLqij4hVv+86+V6E5J5VMCS+oYvb4lYHpuqWR2+fzMJEm/VLLkAMcQi2Esi9 1OOmeMosmcJv0U7+XH+U9Q0yIoJnLK9011OL29DZp4VXOSi0LbLYHf3nt2sDesbE qWThZbmsjsjVMZaDPvBKahGMXsQhTPxe5mO+K32WFkNYSWZmepFrIFVRd48gZcpp fzGAIhGojgt/SiyRqwWIgXXlA6UzBtrc66c0UgEnUNf7K71EUr+uImthbf/+zSu4 JJVUiCYcm7o7Evm/8odb7/q406O79r366ChHGu4219tARAJajGeg1nzunwu6wUYU a/9EeMVlYMR0CY48KczicWus4x1OxvaAsh77D83J/Sx8gCcF1lY= =CRo7 -----END PGP SIGNATURE-----