-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 01 Sep 2026 19:03:49 +0200 Source: thunderbird Architecture: source Version: 1:153.2.0esr-1 Distribution: unstable Urgency: medium Maintainer: Carsten Schoenert <c.schoenert@t-online.de> Changed-By: Carsten Schoenert <c.schoenert@t-online.de> Closes: 880424 882218 883245 900210 909281 914403 917613 928178 949450 949649 955380 961269 1127710 1128672 1145329 Changes: thunderbird (1:153.2.0esr-1) unstable; urgency=medium . [ Carsten Schoenert ] * [cb6c2c5] Merge tag 'debian/1%153.1.0esr-1' into debian/sid * [3c5e98e] d/gbp.conf: Adjust upstream branch to new ESR cycle * [628233d] New upstream version 153.2.0esr Fixed CVE issues in upstream version 153.2 (MFSA 2026-88): CVE-2026-84639: Uninitialized memory in MIME parsing CVE-2026-84640: One byte overflow read in mail parser CVE-2026-84641: Information disclosure due to malicious IMAP server response CVE-2026-84637: Calendar invitation attachments could launch local executables CVE-2026-84642: Allowed UNC hostnames for attachments interpreted as a regular expression CVE-2026-75874: Sandbox escape in the Remote Settings Client component CVE-2026-84118: Use-after-free in the JavaScript: GC component CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component CVE-2026-84120: Use-after-free in the Audio/Video component CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component CVE-2026-84122: Use-after-free in the Audio/Video component CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component CVE-2026-84124: Use-after-free in the DOM: Core & HTML component CVE-2026-84125: Use-after-free in the DOM: Core & HTML component CVE-2026-74952: Privilege escalation in the Application Update component CVE-2026-84129: Site isolation issue in the DOM: Navigation component CVE-2026-84130: Information disclosure in the Graphics: WebGPU component CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component CVE-2026-84132: Information disclosure in the Networking: HTTP component CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component CVE-2026-84134: Other issue in the Profile Backup component CVE-2026-84136: Other issue in the DOM: Navigation component CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component CVE-2026-84139: Clickjacking issue in the DOM: Events component CVE-2026-84140: Site isolation issue in the DOM: Navigation component CVE-2026-84141: Integer overflow in the Graphics: ImageLib component CVE-2026-84143: Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15 CVE-2026-84144: Internally found bugs fixed in Thunderbird 155 and Thunderbird ESR 153.2 CVE-2026-84145: Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15 (Closes: #1145329, #1128672, #1127710, #928178, #909281, #955380, #882218, #900210, #914403, #917613, #949450, #880424, #883245, #961269, #949649) Checksums-Sha1: bac4eb72b9649c816760856964d09c076e38faf5 8422 thunderbird_153.2.0esr-1.dsc fe79aa4defdc8020c7a02c6df6bb7b563f36adfb 12815688 thunderbird_153.2.0esr.orig-thunderbird-l10n.tar.xz 233dca2b586cd5c74b64334dce706f1e3ca00b80 904710156 thunderbird_153.2.0esr.orig.tar.xz b7cdeda74917b707b255c13b708b09157c5e7db8 556104 thunderbird_153.2.0esr-1.debian.tar.xz 791e62c718ff9918ea5877797a45c0d22738ea38 41146 thunderbird_153.2.0esr-1_amd64.buildinfo Checksums-Sha256: d77eab67b96ee31524426926ef06a4e48ac3b2415ea96d1a7f2128e77ca99ad0 8422 thunderbird_153.2.0esr-1.dsc c33e07a872d250687088a407ce054593f6b0c2f5683e9af8f6632cdeb9700553 12815688 thunderbird_153.2.0esr.orig-thunderbird-l10n.tar.xz 79c01aa5b07f3464d43cc96300141b678a2685c861b9bcc6890e9e6d088f1aeb 904710156 thunderbird_153.2.0esr.orig.tar.xz 533a8015c15e833508f91e121182c5426af50c22ab56a0f1081c0fdda20f39e9 556104 thunderbird_153.2.0esr-1.debian.tar.xz f241204d92ccbacd2171d1e9f151875e6211f07ba8339177364a68d98cca2f95 41146 thunderbird_153.2.0esr-1_amd64.buildinfo Files: ed3769dd9d71c325b0279905fdb13bb5 8422 mail optional thunderbird_153.2.0esr-1.dsc 86caafe71439920cf8a6654c990c9fa2 12815688 mail optional thunderbird_153.2.0esr.orig-thunderbird-l10n.tar.xz b2c0d7f65a9cd572aa2a1f30644775cc 904710156 mail optional thunderbird_153.2.0esr.orig.tar.xz 2ef3d8fe96862cfda6fcee8e46c50a71 556104 mail optional thunderbird_153.2.0esr-1.debian.tar.xz dfc69d6380f67a4b97137b4f7fe5d71b 41146 mail optional thunderbird_153.2.0esr-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmqYPuMACgkQgwFgFCUd HbDucw//V9bDtLsvpm/xw02HRxdA7FPVmYjP9k4oWIf634i82Cu+o8UHksHNYfip qCMpgrwR+LXPDfnF/UZeW8AaMvX69C3Be2b33TB/7Cgjo9kIJI0/4IhKhp0CJiwn jjtRkyVNLDDDYMNJU4pbkQR/PDlyjG2N/RSqfylR/iC1KUO70D6XkIAkw6AoUEoP 1s+Ly52fdF6SSvLRwcTQtt/k7xKRILVIda+uDey/LAz40TszDTbwbSrY+/tkWBtW 5aLA+eE6YR/aKxlW7+rUj1IhaW0FzlAEbUCrl2li5l0oSw4JqqPGmYSUuQyfJXI1 V8eytDOU5tl8uYGb1ixlYB5nmbRrT815bBw0Fddw5rR+7j9QD/QlSRfOHgP+ppm5 bWfyiPaI0mCUTm5trv6ECl3BZC4/rpWAmn80ucxfJoocqlEl+mALDV5DCz0sSU4p ErQ8zZYHZfgfiZbwSi2jElhUwWvAD8r0AmsZSxaZJEjRQeq+DGj56kK0+mnpIMQ1 hzWr1OBr+Tt2FZw4n94GAZ077U8SFlGTQSMTdk+vaT6wypuWY2TtJqiPW2uk8B1v 2HZd5KIBFdYgiChNyZEa1RpfCX+xhjXIdE6jc1yhpZ8rmwHLVVzY4nfaUCoXm70E OcNnneYzELnz8mbI3NXZ9iyjPXAMdyskdSijmOgPMlC7pNh0pks= =sQE4 -----END PGP SIGNATURE-----