-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 20 Aug 2026 17:56:08 +0200
Source: thunderbird
Architecture: source
Version: 1:140.14.0esr-1
Distribution: unstable
Urgency: medium
Maintainer: Carsten Schoenert <c.schoenert@t-online.de>
Changed-By: Carsten Schoenert <c.schoenert@t-online.de>
Changes:
thunderbird (1:140.14.0esr-1) unstable; urgency=medium
.
* [b882591] New upstream version 140.14.0esr
Fixed CVE issues in upstream version 140.14 (MFSA 2026-79):
CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL
component
CVE-2026-74935: Privilege escalation in the DOM: Networking component
CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component
CVE-2026-74939: Privilege escalation in the DOM: Navigation component
CVE-2026-74940: Use-after-free in the Graphics: Text component
CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL
component
CVE-2026-74942: Privilege escalation in the Remote Settings Client
component
CVE-2026-74943: Use-after-free in the Graphics: ImageLib component
CVE-2026-74944: Use-after-free in the DOM: Core & HTML component
CVE-2026-74945: Information disclosure in the Graphics: Text component
CVE-2026-74946: Privilege escalation due to incorrect boundary
conditions in the Graphics: CanvasWebGL component
CVE-2026-74948: Information disclosure in the Graphics component
CVE-2026-74949: Privilege escalation due to use-after-free in the
Graphics: Canvas2D component
CVE-2026-74953: Privilege escalation in the Networking: Cookies
component
CVE-2026-74957: Mitigation bypass in the Safe Browsing component
CVE-2026-74959: Mitigation bypass in the Storage: Cache API component
CVE-2026-74960: Site isolation issue in the WebExtensions component
CVE-2026-74962: Site isolation issue in the Networking: Cookies
component
CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies
component
CVE-2026-74964: Integer overflow in the Graphics component
CVE-2026-74965: Privilege escalation in the Shell Integration component
CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback
component
CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component
CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus
Handling component
CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions
component
CVE-2026-74973: Race condition, use-after-free in the Graphics component
CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib
component
CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT
component
CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component
CVE-2026-74987: Internally found bugs fixed in Thunderbird ESR 140.14,
Thunderbird ESR 153.1 and Thunderbird 154
CVE-2026-74990: Internally found bugs fixed in Thunderbird ESR 140.14,
Thunderbird ESR 153.1 and Thunderbird 154
Checksums-Sha1:
122d1c0abdc5d596c942dce8bf91e97b9b486741 8472 thunderbird_140.14.0esr-1.dsc
44cabead132a25826cde3d21378c90e710a47b5e 12265928 thunderbird_140.14.0esr.orig-thunderbird-l10n.tar.xz
08c39c6dca94825265cea0c95dc3550fceee2bab 789375948 thunderbird_140.14.0esr.orig.tar.xz
a99b06e1870946194859fad6c8acd974fd85a2f1 572200 thunderbird_140.14.0esr-1.debian.tar.xz
482047ed85fe161d0d8ba94f23a8a18a2a672e18 41407 thunderbird_140.14.0esr-1_amd64.buildinfo
Checksums-Sha256:
bdb6d1a57fc46940769c6c99e35cc1833475490bd0253ef4110cafada5a4d887 8472 thunderbird_140.14.0esr-1.dsc
38a37d19a9cdb35a79e80ed6d02e42e27eb8a554ac639e598e3bbbbdac310af3 12265928 thunderbird_140.14.0esr.orig-thunderbird-l10n.tar.xz
ea55f375176a9aca3742b47a1ef0ba5693ee45ca857bf8f00135c199937f4079 789375948 thunderbird_140.14.0esr.orig.tar.xz
b79bd7ed6be5ac0743bb37b49d37c7ccb1cdae1327974a5f2f5ce24834b9e291 572200 thunderbird_140.14.0esr-1.debian.tar.xz
3dde504044dc6e7662e2614a109fe5a79996e9eb95c76a187372d4983aa14d90 41407 thunderbird_140.14.0esr-1_amd64.buildinfo
Files:
edfcc902b435a11d513b1109dbe4154d 8472 mail optional thunderbird_140.14.0esr-1.dsc
f6d3ac4874fd9374f4931f83b3fe781c 12265928 mail optional thunderbird_140.14.0esr.orig-thunderbird-l10n.tar.xz
5095535532df019176a7c4928bca35ad 789375948 mail optional thunderbird_140.14.0esr.orig.tar.xz
7bc0ac7204f9c13bb1226ec0258337b3 572200 mail optional thunderbird_140.14.0esr-1.debian.tar.xz
67ca0e9f1a0c2adf3c9149582210f9cd 41407 mail optional thunderbird_140.14.0esr-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmqHQn4ACgkQgwFgFCUd
HbC9AA/9ECFa0+k9QQL0RGe4JGZAXPnRNVaDq66UEPgn8YIyIqq6w73cNC4CL8+0
QmcWJ+J0selRTtbSOUurJR+zb+q+F+GSJmyEdA0WvixRjHku5U7GKl3logArx2q8
fUX/twBZGMYeCnnVIOPlAe05l9e2w7uU6w4BzSk7zH+2PKhmOBSNe0mI6zMsm91g
Iw0FrvmuxvFWV5c6q2yKmELG7yhmzCmImuncVnCSTAtVGwucqSGgfSaamIKCLEyX
fQQH0eun5YgllbNvBd1gl5X9EtM03sbquori7IT7eNEbk1XQomiYO4UZfNoGnj9h
ErKC2xPX6TxjcgH4TG1Y24GPt8GFryVKnMjpK0/TOgv2unvmTUwyawGkb9jQN2hZ
3mug4kmJOtoYPWK+Cr5tPYm1Ig2Iw1pN/to0cbwMFv9vLxFgilc/bzoF5SJDBB1K
MUgHBs+v+uDYVKEC6lOxhC4FoGKV8ZDtlQbBeGXNuDeNlhqgygryh5Q41F1f1dAN
Fft3sQNK/PYGZXj572PXkNuKmHlczR9LHkBY+NRwY4ogIC1e76YYmxpp2QMZRVQv
vPRO5W8PPrW5Qu1HiZ5BNv8teNK8QaBksN1bAjCZN+vbWnxs/peIC1vGQabTYqgG
gymf+pTc1A+E4hmkgy62yRzeaFJ9O/30MlTcmezLBKgz02elFqk=
=8PUq
-----END PGP SIGNATURE-----