-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 25 Oct 2025 15:10:56 +0200
Source: thunderbird
Architecture: source
Version: 1:140.4.0esr-1
Distribution: unstable
Urgency: medium
Maintainer: Carsten Schoenert <c.schoenert@t-online.de>
Changed-By: Christoph Goehre <chris@sigxcpu.org>
Changes:
 thunderbird (1:140.4.0esr-1) unstable; urgency=medium
 .
   * [d34f599] New upstream version 140.4.0esr
     Fixed CVE issues in upstream version 140.4 (MFSA 2025-85):
     CVE-2025-11708: Use-after-free in MediaTrackGraphImpl::GetInstance()
     CVE-2025-11709: Out of bounds read/write in a privileged process triggered
                     by WebGL textures
     CVE-2025-11710: Cross-process information leaked due to malicious IPC
                     messages
     CVE-2025-11711: Some non-writable Object properties could be modified
     CVE-2025-11712: An OBJECT tag type attribute overrode browser behavior on
                     web resources without a content-type
     CVE-2025-11713: Potential user-assisted code execution in “Copy as cURL”
                     command
     CVE-2025-11714: Memory safety bugs fixed in Firefox ESR 115.29, Firefox
                     ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and
                     Thunderbird 144
     CVE-2025-11715: Memory safety bugs fixed in Firefox ESR 140.4, Thunderbird
                     ESR 140.4, Firefox 144 and Thunderbird 144
Checksums-Sha1:
 974c9faae1c70b533d0d52b16a3dbc9f33be9a23 8437 thunderbird_140.4.0esr-1.dsc
 19b8de5e8bdbdce3f6c9b48b440a873bc05ad6e9 12191888 thunderbird_140.4.0esr.orig-thunderbird-l10n.tar.xz
 3f00475893da68a1fb2b839cb91499e7a16e375a 785308512 thunderbird_140.4.0esr.orig.tar.xz
 306d5c0a6ca2e7c811efe065858c58c54a6ad953 551928 thunderbird_140.4.0esr-1.debian.tar.xz
 1ca5415a69c4f506536533c0ef09366765590408 7951 thunderbird_140.4.0esr-1_source.buildinfo
Checksums-Sha256:
 443fba883f0f384f630db1acc6f79086f3eff4374d7c7718bcd9b46cc1e68e2e 8437 thunderbird_140.4.0esr-1.dsc
 74be432f655886571f72352876c861f53a4c56021b771cd4c78a08f04f6f2950 12191888 thunderbird_140.4.0esr.orig-thunderbird-l10n.tar.xz
 6065e07dbb57422c9c582ccaf78100e16ff9f29ab364e887970dd670ff21de74 785308512 thunderbird_140.4.0esr.orig.tar.xz
 becd8396b1cbad04314a2900a64324b67e38c90f215d9282caa7885c53179229 551928 thunderbird_140.4.0esr-1.debian.tar.xz
 9850f8da47511cf94448d9be796653608fcd144aab62d1381b3b4597fa7f18a9 7951 thunderbird_140.4.0esr-1_source.buildinfo
Files:
 32e85ebdeb1b7e2aafa12202eab0ff24 8437 mail optional thunderbird_140.4.0esr-1.dsc
 39970874c0d2549e127ef534c91268bc 12191888 mail optional thunderbird_140.4.0esr.orig-thunderbird-l10n.tar.xz
 c649fd8bdeaf8a9f9679dd05737b9090 785308512 mail optional thunderbird_140.4.0esr.orig.tar.xz
 f9b8dc7f1fc4d89fc585dfc1ee520342 551928 mail optional thunderbird_140.4.0esr-1.debian.tar.xz
 3fcc6cbeec4574a3ab8f85b404b3c115 7951 mail optional thunderbird_140.4.0esr-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEi5SBnCVVcKN0tizNJuPIdadEIO8FAmj87jAACgkQJuPIdadE
IO8r4w//QLQISG73TF2GFrPLAzTUDkI7GyEZ7gQNN58qhkTf5W8iJ/58dBYXONaz
cFFFKI5o8gmM3tesaq0VERcyIvfuI5zOpsqm2e/uJEoiDyTmBXTxrnBKTQ2dS/rF
XRFicNA8vXQdshg4TCzMJ0si5qRK/93rZnzzYmwNaJqlHoTu3Mhqx1MsTA1rgImM
sYy7RyFX7RgT5IAauVRawmRIB2OaOH+a8vFAzfb8zZCwEJ6l5Er7/Bjak8EyU0Jf
xkcwd04WRsSK1bejEw+2ezirHuEFE4XN2JWyi9nUOdLAK0Oacay2gU90JCaLssEl
5jyzx/t2xESv3znEmRI6Y8bpy+TO4Fl0s9YRvWKLiz//6EdvoJR8r3q8mKDB5lSR
Xoyz23A2sREm0MUj079sdk4BANc1u1BXyvW+wcLBIvw1ge9WD0RuuQwA8peI7ksI
7yZjnXifiU4cMX+uVxBoLRe+J6aegBg2/eovp282AJxHkgikqJziyItpxxQ35tZm
66/DFFnYlUNwXidEpe03Fh9c7W42JWY165SN2ULmcns/Ls5WWYIVj+w3kU7D7znY
eKt6TQRwx4sim2Pgovd+CEhhNGlXyxU0Xo+laj7ik/xFJ62XVB9b5LG3Qx6R3y6V
UlBqnnmv/KPvcEJKdYLKohDb8C4xLKF/LwaAMyvwj5h3sZpgMXA=
=kyz+
-----END PGP SIGNATURE-----