-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 07 Sep 2024 18:44:59 +0200 Source: thunderbird Architecture: source Version: 1:128.2.0esr-1 Distribution: unstable Urgency: medium Maintainer: Carsten Schoenert <c.schoenert@t-online.de> Changed-By: Carsten Schoenert <c.schoenert@t-online.de> Changes: thunderbird (1:128.2.0esr-1) unstable; urgency=medium . * [33f11cd] d/create-upstream-tarballs.py: Ignore version 130.0 * [56e8a06] New upstream version 128.2.0esr Fixed CVE issues in upstream version 128.2 (MFSA 2024-43): CVE-2024-8394: Crash when aborting verification of OTR chat CVE-2024-8385: WASM type confusion involving ArrayTypes CVE-2024-8381: Type confusion when looking up a property name in a "with" block CVE-2024-8382: Internal event interfaces were exposed to web content when browser EventHandler listener callbacks ran CVE-2024-8384: Garbage collection could mis-color cross-compartment objects in OOM conditions CVE-2024-8386: SelectElements could be shown over another site if popups are allowed CVE-2024-8387: Memory safety bugs fixed in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2 Checksums-Sha1: f9776a6f1e8220c49024ab01b08f81d4b63d052d 8505 thunderbird_128.2.0esr-1.dsc 6505fc891f9e995110a8545958093f393cafb95f 13335996 thunderbird_128.2.0esr.orig-thunderbird-l10n.tar.xz ccecc18eaafd029b405b2878aa16f382d6e1760a 701962100 thunderbird_128.2.0esr.orig.tar.xz 95ddbd3d23a3cc9767390f9d6cea5471ccce2953 545992 thunderbird_128.2.0esr-1.debian.tar.xz e4fcc9138043dab7982dc44b20f676977f7ffcf0 41625 thunderbird_128.2.0esr-1_amd64.buildinfo Checksums-Sha256: b8763b153e61688dc09d31212e2877681dcee06706eea651d0d39ed734c96d02 8505 thunderbird_128.2.0esr-1.dsc 7d089953779b35d14f8d282c7b4a813eed3647a101cde3a79f30fe93778b5fdd 13335996 thunderbird_128.2.0esr.orig-thunderbird-l10n.tar.xz aa4186319cd015d342d00058b4112229c3244da4249d30fc073cfce09cc39a63 701962100 thunderbird_128.2.0esr.orig.tar.xz 15eb2011a9fa3c55dc207c307514288717e6e2ca5e6e1070403ea45ca62050d6 545992 thunderbird_128.2.0esr-1.debian.tar.xz ad9fd6d826249cb0678d6aa2b2f57699a9ba0812462fc16ded62f67080f2b057 41625 thunderbird_128.2.0esr-1_amd64.buildinfo Files: c7bdd265d3c12909c7165b99693daa05 8505 mail optional thunderbird_128.2.0esr-1.dsc a0b25503884c39bb87fb5b79b65f4854 13335996 mail optional thunderbird_128.2.0esr.orig-thunderbird-l10n.tar.xz e05675ed3cdf0a3a658d7207f5c387f5 701962100 mail optional thunderbird_128.2.0esr.orig.tar.xz bf1749d6f7d8868d6019c3fd51e2b03d 545992 mail optional thunderbird_128.2.0esr-1.debian.tar.xz 7ddfa086554df6df15d3e45f80760dfd 41625 mail optional thunderbird_128.2.0esr-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmbgn+MACgkQgwFgFCUd HbAKMA/+IVGYgQPExp35yUOvH4RrkcchSTLFIK+ZKWtN0wEA++jKSp1G5ZjbF+Or bVD1ufgw5ubf2bfCM4oIcA4DNuIHvJ6mw0vVMNx6X+jR2ELJHuYEUQWiQBnkCTDq IZ9thmNwa7zHSl517luhzpbtO5VwwGJMjzTe9cXxVbkQH02Gw/LaHmA2x/bYa50V 4vYDGPtA79px3KQ8lTlBBdZuV5djcw6xpxdnXB7OFtYno1FUBf1PdCFzCf3StH0W 20J/7tEyaV9h0TJGWiqXUZdQdQjPGV7UkhMQW67psQFKXEcjzsejj2JuUfnESfMU QGnGTYg+caW0cBOk/IuuTra1ccaz0RN/SbyXmnMPK6pnIfnnfJJobGlFM4/ciQfK /mx8jrwlfzr/Tk9Sj77jhc3Nl4IuXzPf5qwBrIPvg8ikGm1XQ7ltF4DChyV9EKgQ Ax22sq+YTW/owRJ8Z4o8SbI0c6pnIfM5ysMd+UWe9NQxeXVdtFGWYNNWniRRdjla HqLsfTDbDZAWBZSJpAa4YsZbz0hz3l5OwwoXHX8usj66ngdj/GM86Olfd8uoAqa6 tIdXU0QbY0rztb9llhqRPbCTXZGxmUt9G0HosYyZPBei/UE2jx9oEvxsTP+PB8B/ yuMloTKbLlyiUSRQAGJaG4iDnQn07W9Py+EehfseK/fEvrXgbfs= =6HIB -----END PGP SIGNATURE-----