-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 04 Aug 2023 19:48:57 +0200 Source: thunderbird Architecture: source Version: 1:102.14.0-1~deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: Carsten Schoenert Changed-By: Carsten Schoenert Changes: thunderbird (1:102.14.0-1~deb12u1) bookworm-security; urgency=medium . * [bcc7c87] New upstream version 102.14.0 Fixed CVE issues in upstream version 102.14 (MFSA 2023-32): CVE-2023-4045: Offscreen Canvas could have bypassed cross-origin restrictions CVE-2023-4046: Incorrect value used during WASM compilation CVE-2023-4047: Potential permissions request bypass via clickjacking CVE-2023-4048: Crash in DOMParser due to out-of-memory conditions CVE-2023-4049: Fix potential race conditions when releasing platform objects CVE-2023-4050: Stack buffer overflow in StorageManager CVE-2023-4055: Cookie jar overflow caused unexpected cookie jar state CVE-2023-4056: Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1, Firefox ESR 102.14, Thunderbird 115.1, and Thunderbird 102.14 * Rebuild for bookworm-security Checksums-Sha1: 5328bae1df2f0f9ba0f77929bf30e85567898907 8538 thunderbird_102.14.0-1~deb12u1.dsc 1be741d5770ac017238ea57ef1cbe0bc8c666594 12634792 thunderbird_102.14.0.orig-thunderbird-l10n.tar.xz 9cb9678b5feb7cbe79226a598bd9174b4ebda3d7 520163316 thunderbird_102.14.0.orig.tar.xz d3912b07e3a8dc4776fb9139d1474b06476a7227 548572 thunderbird_102.14.0-1~deb12u1.debian.tar.xz Checksums-Sha256: 9b1e12468e0c7d82acffbe249bc649a4a8397d63a6c29d5c9c5f1c57955a263b 8538 thunderbird_102.14.0-1~deb12u1.dsc 14c66b06cbf3d1dcd495206f6c199c8d9caea2c6148e759c7a1e757e83b1a2ac 12634792 thunderbird_102.14.0.orig-thunderbird-l10n.tar.xz 72da659162f70472d41f9cdb1a16c1aca707e6baf872847d1bf9049f950a21af 520163316 thunderbird_102.14.0.orig.tar.xz 26323699fc11882618539d0e7fff4f95644497bf8418c96b6d7d7f1b40e62d99 548572 thunderbird_102.14.0-1~deb12u1.debian.tar.xz Files: 617ee0feaab5547993346055d0e5ce82 8538 mail optional thunderbird_102.14.0-1~deb12u1.dsc fdcb2e93138c2311daed16e743ca3bf1 12634792 mail optional thunderbird_102.14.0.orig-thunderbird-l10n.tar.xz b934960c2b481c134caba74992e95ba1 520163316 mail optional thunderbird_102.14.0.orig.tar.xz d3d67f3f764e0b41aa372a878da145a3 548572 mail optional thunderbird_102.14.0-1~deb12u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmTNSaQACgkQgwFgFCUd HbAi2g//ehiBrr7YT0hIO09X6T0MZVv7Cy9iT4GKYMUkS9CR8IMPGq1SzRM9nAZB 3WjSFwNOO647hGrsV+g+weAyiL4MhyAUFfIJ/g/XDNourWBrwTdp+OazNy3cfDpz qwWKPzuOobrxrF8l2H19dxRfJViFjRIw89W5HIMUOyAH9rdt1190Ar3OGHFjEAkl b70GLvQzhQktaDGhIu723a4KP5u5ZuL8ozRnSu8f09pZspyTLQj1H3pLAowJ1KCF dHeqf9dmwPgTpiEWXVamj6L1+oPAGwmRnxHYWfJDWfDaRXu4tcCH22fPUgXxxZM+ u2eFwtkhgzCOKgYKkQg4/eSxHCgKMS59Nf+H4VylOPwZMFMOpxLP1koFve37V+ny 6A3zv3u/6PLUPFJQfeKcpJotibUZ4OhbZ+qcgpieyH0wDJ75TAw6bbah+wVjJLAA FPjPYfLUsIWggawvTFTw9RWPxshzLPNaQUyYmzomzScrkkYD59MiQdF3339OXKAp ZsKvD9wFTwAo5WYcfgBHvtxRxRKLMf9dMXeWoDtXa3Lia0i3/mQTthmuwKlXkcdt EC9U2TDCOG76ZyPvBZ8leoPt0XO9gqKPjwvf5rqtNHO2nbV/eNha/s8XwAz+jykS 9ebmWM1wFm/FYRNAyg3IN1SKoZjTrhMTL1qeyMwQaGP2qI7gwqs= =oDF3 -----END PGP SIGNATURE-----