Debian Package Tracker
Register | Log in
Subscribe

thunderbird

mail/news client with RSS, chat and integrated spam filter support

Choose email to subscribe with

general
  • source: thunderbird (main)
  • version: 1:140.4.0esr-1
  • maintainer: Carsten Schoenert (DMD)
  • uploaders: Christoph Goehre [DMD]
  • arch: all amd64 arm64 i386 mips64el ppc64 ppc64el
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1:115.12.0-1~deb11u1
  • o-o-sec: 1:140.4.0esr-1~deb11u1
  • o-o-p-u: 1:115.14.0-1~deb11u1
  • oldstable: 1:128.14.0esr-1~deb12u1
  • old-sec: 1:140.4.0esr-1~deb12u1
  • stable: 1:128.14.0esr-1~deb13u1
  • stable-sec: 1:140.4.0esr-1~deb13u1
  • testing: 1:140.3.1esr-1
  • unstable: 1:140.4.0esr-1
  • exp: 1:143.0.1-1
versioned links
  • 1:91.13.0-1~deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:115.12.0-1~deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:115.14.0-1~deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:115.15.0-1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:115.16.0esr-1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:128.14.0esr-1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:128.14.0esr-1~deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:140.3.1esr-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:140.4.0esr-1~deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:140.4.0esr-1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:140.4.0esr-1~deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:140.4.0esr-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:143.0.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • thunderbird (128 bugs: 0, 105, 23, 0)
  • thunderbird-l10n-af
  • thunderbird-l10n-all
  • thunderbird-l10n-ar
  • thunderbird-l10n-ast
  • thunderbird-l10n-be
  • thunderbird-l10n-bg
  • thunderbird-l10n-br
  • thunderbird-l10n-ca
  • thunderbird-l10n-cak
  • thunderbird-l10n-cs
  • thunderbird-l10n-cy
  • thunderbird-l10n-da (1 bugs: 0, 0, 1, 0)
  • thunderbird-l10n-de
  • thunderbird-l10n-dsb
  • thunderbird-l10n-el
  • thunderbird-l10n-en-ca
  • thunderbird-l10n-en-gb
  • thunderbird-l10n-es-ar
  • thunderbird-l10n-es-es
  • thunderbird-l10n-es-mx
  • thunderbird-l10n-et
  • thunderbird-l10n-eu
  • thunderbird-l10n-fi
  • thunderbird-l10n-fr (3 bugs: 0, 1, 2, 0)
  • thunderbird-l10n-fy-nl
  • thunderbird-l10n-ga-ie
  • thunderbird-l10n-gd
  • thunderbird-l10n-gl
  • thunderbird-l10n-he
  • thunderbird-l10n-hr
  • thunderbird-l10n-hsb
  • thunderbird-l10n-hu
  • thunderbird-l10n-hy-am
  • thunderbird-l10n-id
  • thunderbird-l10n-is
  • thunderbird-l10n-it
  • thunderbird-l10n-ja
  • thunderbird-l10n-ka
  • thunderbird-l10n-kab
  • thunderbird-l10n-kk
  • thunderbird-l10n-ko
  • thunderbird-l10n-lt
  • thunderbird-l10n-lv
  • thunderbird-l10n-ms
  • thunderbird-l10n-nb-no
  • thunderbird-l10n-nl (1 bugs: 0, 1, 0, 0)
  • thunderbird-l10n-nn-no
  • thunderbird-l10n-pa-in
  • thunderbird-l10n-pl
  • thunderbird-l10n-pt-br
  • thunderbird-l10n-pt-pt
  • thunderbird-l10n-rm
  • thunderbird-l10n-ro
  • thunderbird-l10n-ru
  • thunderbird-l10n-sk
  • thunderbird-l10n-sl
  • thunderbird-l10n-sq
  • thunderbird-l10n-sr
  • thunderbird-l10n-sv-se
  • thunderbird-l10n-th
  • thunderbird-l10n-tr
  • thunderbird-l10n-uk
  • thunderbird-l10n-uz
  • thunderbird-l10n-vi
  • thunderbird-l10n-zh-cn
  • thunderbird-l10n-zh-tw
action needed
7 security issues in forky high

There are 7 open security issues in forky.

7 important issues:
  • CVE-2025-11708: Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.
  • CVE-2025-11709: A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.
  • CVE-2025-11710: A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.
  • CVE-2025-11711: There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.
  • CVE-2025-11712: A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This could have contributed to an XSS on a site that unsafely serves files without a content-type header. This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.
  • CVE-2025-11714: Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.
  • CVE-2025-11715: Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.
Created: 2025-10-14 Last update: 2025-10-27 08:31
debian/patches: 1 patch with invalid metadata, 18 patches to forward upstream high

Among the 22 debian patches available in version 1:140.4.0esr-1 of the package, we noticed the following issues:

  • 1 patch with invalid metadata that ought to be fixed.
  • 18 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2025-10-26 08:02
lintian reports 2 errors and 1 warning high
Lintian reports 2 errors and 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2025-10-26 Last update: 2025-10-26 03:31
2 bugs tagged patch in the BTS normal
The BTS contains patches fixing 2 bugs, consider including or untagging them.
Created: 2025-01-06 Last update: 2025-10-29 10:00
Depends on packages which need a new maintainer normal
The packages that thunderbird depends on which need a new maintainer are:
  • libidl (#738870)
    • Build-Depends: libidl-dev
  • hunspell-kk (#879871)
    • Recommends: hunspell-kk
  • ifrench-gut (#1006643)
    • Recommends: myspell-fr-gut
  • uzbek-wordlist (#841696)
    • Recommends: hunspell-uz
  • wireless-tools (#963896)
    • Build-Depends: libiw-dev
Created: 2019-11-22 Last update: 2025-10-29 09:30
Fails to build during reproducibility testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2025-10-20 Last update: 2025-10-29 06:30
1 open merge request in Salsa normal
There is 1 open merge request for this package on Salsa. You should consider reviewing and/or merging these merge requests.
Created: 2025-09-20 Last update: 2025-09-20 16:02
AppStream hints: 1 warning normal
AppStream found metadata issues for packages:
  • thunderbird: 1 warning
You should get rid of them to provide more metadata about this software.
Created: 2021-12-22 Last update: 2021-12-22 06:06
testing migrations
  • excuses:
    • Migration status for thunderbird (1:140.3.1esr-1 to 1:140.4.0esr-1): Waiting for test results or another package, or too young (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Too young, only 3 of 5 days old
    • Additional info:
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/t/thunderbird.html
    • ∙ ∙ uninstallable on arch s390x (which is allowed), not running autopkgtest there
    • ∙ ∙ autopkgtest for thunderbird/1:140.4.0esr-1: amd64: Pass, arm64: Test triggered (failure will be ignored), i386: Pass, ppc64el: Test triggered (failure will be ignored), riscv64: Test triggered (failure will be ignored)
    • ∙ ∙ Waiting for reproducibility test results on amd64 - info ♻
    • ∙ ∙ Waiting for reproducibility test results on arm64 - info ♻
    • Not considered
news
[rss feed]
  • [2025-10-26] Accepted thunderbird 1:140.4.0esr-1~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Christoph Goehre)
  • [2025-10-26] Accepted thunderbird 1:140.4.0esr-1~deb12u1 (source) into oldstable-security (Debian FTP Masters) (signed by: Christoph Goehre)
  • [2025-10-26] Accepted thunderbird 1:140.4.0esr-1~deb11u1 (source) into oldoldstable-security (Christoph Goehre)
  • [2025-10-25] Accepted thunderbird 1:140.4.0esr-1 (source) into unstable (Christoph Goehre)
  • [2025-10-15] thunderbird 1:140.3.1esr-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-04] Accepted thunderbird 1:140.3.1esr-1 (source) into unstable (Carsten Schoenert)
  • [2025-10-03] Accepted thunderbird 1:143.0.1-1 (source) into experimental (Carsten Schoenert)
  • [2025-09-30] Removed 1:140.2.0esr-1 from experimental (Debian FTP Masters)
  • [2025-09-30] thunderbird 1:140.3.0esr-1 MIGRATED to testing (Debian testing watch)
  • [2025-09-25] Accepted thunderbird 1:140.3.0esr-1~deb11u1 (source) into oldoldstable-security (Emilio Pozuelo Monfort)
  • [2025-09-25] Accepted thunderbird 1:140.3.0esr-1~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Emilio Pozuelo Monfort)
  • [2025-09-25] Accepted thunderbird 1:140.3.0esr-1~deb12u1 (source) into oldstable-security (Debian FTP Masters) (signed by: Emilio Pozuelo Monfort)
  • [2025-09-20] Accepted thunderbird 1:140.3.0esr-1 (source) into unstable (Carsten Schoenert)
  • [2025-08-29] Accepted thunderbird 1:128.14.0esr-1~deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Carsten Schoenert)
  • [2025-08-28] Accepted thunderbird 1:128.14.0esr-1~deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Carsten Schoenert)
  • [2025-08-27] thunderbird 1:128.14.0esr-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-24] Accepted thunderbird 1:140.2.0esr-1 (source) into experimental (Carsten Schoenert)
  • [2025-08-24] Accepted thunderbird 1:128.14.0esr-1~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Carsten Schoenert)
  • [2025-08-24] Accepted thunderbird 1:128.14.0esr-1~deb12u1 (source) into oldstable-security (Debian FTP Masters) (signed by: Carsten Schoenert)
  • [2025-08-23] Accepted thunderbird 1:128.14.0esr-1~deb11u1 (source) into oldoldstable-security (Carsten Schoenert)
  • [2025-08-21] Accepted thunderbird 1:128.14.0esr-1 (source) into unstable (Carsten Schoenert)
  • [2025-08-10] Accepted thunderbird 1:140.1.1esr-1 (source) into experimental (Carsten Schoenert)
  • [2025-07-30] Accepted thunderbird 1:140.1.0esr-1 (source) into experimental (Carsten Schoenert)
  • [2025-07-30] thunderbird 1:128.13.0esr-1 MIGRATED to testing (Debian testing watch)
  • [2025-07-28] Accepted thunderbird 1:128.13.0esr-1~deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Christoph Goehre)
  • [2025-07-27] Accepted thunderbird 1:128.13.0esr-1~deb12u1 (source) into stable-security (Debian FTP Masters) (signed by: Christoph Goehre)
  • [2025-07-25] Accepted thunderbird 1:128.13.0esr-1~deb11u1 (source) into oldstable-security (Christoph Goehre)
  • [2025-07-24] Accepted thunderbird 1:128.13.0esr-1 (source) into unstable (Christoph Goehre)
  • [2025-07-21] Accepted thunderbird 1:140.0.1esr-1 (source) into experimental (Christoph Goehre)
  • [2025-07-09] Accepted thunderbird 1:128.12.0esr-1~deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Christoph Goehre)
  • 1
  • 2
bugs [bug history graph]
  • all: 339 342
  • RC: 0
  • I&N: 255 257
  • M&W: 84 85
  • F&P: 0
  • patch: 2
links
  • homepage
  • lintian (2, 1)
  • buildd: logs, exp, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • l10n (-, 73)
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2:1snap1-0ubuntu3
  • 387 bugs (4 patches)
  • patches for 2:1snap1-0ubuntu3

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing