Accepted thunderbird 1:102.14.0-1~deb12u1 (source) into proposed-updates
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 04 Aug 2023 19:48:57 +0200
Source: thunderbird
Architecture: source
Version: 1:102.14.0-1~deb12u1
Distribution: bookworm-security
Urgency: medium
Maintainer: Carsten Schoenert <c.schoenert@t-online.de>
Changed-By: Carsten Schoenert <c.schoenert@t-online.de>
Changes:
thunderbird (1:102.14.0-1~deb12u1) bookworm-security; urgency=medium
.
* [bcc7c87] New upstream version 102.14.0
Fixed CVE issues in upstream version 102.14 (MFSA 2023-32):
CVE-2023-4045: Offscreen Canvas could have bypassed cross-origin restrictions
CVE-2023-4046: Incorrect value used during WASM compilation
CVE-2023-4047: Potential permissions request bypass via clickjacking
CVE-2023-4048: Crash in DOMParser due to out-of-memory conditions
CVE-2023-4049: Fix potential race conditions when releasing platform objects
CVE-2023-4050: Stack buffer overflow in StorageManager
CVE-2023-4055: Cookie jar overflow caused unexpected cookie jar state
CVE-2023-4056: Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1,
Firefox ESR 102.14, Thunderbird 115.1, and Thunderbird 102.14
* Rebuild for bookworm-security
Checksums-Sha1:
5328bae1df2f0f9ba0f77929bf30e85567898907 8538 thunderbird_102.14.0-1~deb12u1.dsc
1be741d5770ac017238ea57ef1cbe0bc8c666594 12634792 thunderbird_102.14.0.orig-thunderbird-l10n.tar.xz
9cb9678b5feb7cbe79226a598bd9174b4ebda3d7 520163316 thunderbird_102.14.0.orig.tar.xz
d3912b07e3a8dc4776fb9139d1474b06476a7227 548572 thunderbird_102.14.0-1~deb12u1.debian.tar.xz
Checksums-Sha256:
9b1e12468e0c7d82acffbe249bc649a4a8397d63a6c29d5c9c5f1c57955a263b 8538 thunderbird_102.14.0-1~deb12u1.dsc
14c66b06cbf3d1dcd495206f6c199c8d9caea2c6148e759c7a1e757e83b1a2ac 12634792 thunderbird_102.14.0.orig-thunderbird-l10n.tar.xz
72da659162f70472d41f9cdb1a16c1aca707e6baf872847d1bf9049f950a21af 520163316 thunderbird_102.14.0.orig.tar.xz
26323699fc11882618539d0e7fff4f95644497bf8418c96b6d7d7f1b40e62d99 548572 thunderbird_102.14.0-1~deb12u1.debian.tar.xz
Files:
617ee0feaab5547993346055d0e5ce82 8538 mail optional thunderbird_102.14.0-1~deb12u1.dsc
fdcb2e93138c2311daed16e743ca3bf1 12634792 mail optional thunderbird_102.14.0.orig-thunderbird-l10n.tar.xz
b934960c2b481c134caba74992e95ba1 520163316 mail optional thunderbird_102.14.0.orig.tar.xz
d3d67f3f764e0b41aa372a878da145a3 548572 mail optional thunderbird_102.14.0-1~deb12u1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmTNSaQACgkQgwFgFCUd
HbAi2g//ehiBrr7YT0hIO09X6T0MZVv7Cy9iT4GKYMUkS9CR8IMPGq1SzRM9nAZB
3WjSFwNOO647hGrsV+g+weAyiL4MhyAUFfIJ/g/XDNourWBrwTdp+OazNy3cfDpz
qwWKPzuOobrxrF8l2H19dxRfJViFjRIw89W5HIMUOyAH9rdt1190Ar3OGHFjEAkl
b70GLvQzhQktaDGhIu723a4KP5u5ZuL8ozRnSu8f09pZspyTLQj1H3pLAowJ1KCF
dHeqf9dmwPgTpiEWXVamj6L1+oPAGwmRnxHYWfJDWfDaRXu4tcCH22fPUgXxxZM+
u2eFwtkhgzCOKgYKkQg4/eSxHCgKMS59Nf+H4VylOPwZMFMOpxLP1koFve37V+ny
6A3zv3u/6PLUPFJQfeKcpJotibUZ4OhbZ+qcgpieyH0wDJ75TAw6bbah+wVjJLAA
FPjPYfLUsIWggawvTFTw9RWPxshzLPNaQUyYmzomzScrkkYD59MiQdF3339OXKAp
ZsKvD9wFTwAo5WYcfgBHvtxRxRKLMf9dMXeWoDtXa3Lia0i3/mQTthmuwKlXkcdt
EC9U2TDCOG76ZyPvBZ8leoPt0XO9gqKPjwvf5rqtNHO2nbV/eNha/s8XwAz+jykS
9ebmWM1wFm/FYRNAyg3IN1SKoZjTrhMTL1qeyMwQaGP2qI7gwqs=
=oDF3
-----END PGP SIGNATURE-----
Reply to: