-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 21 Aug 2025 17:45:12 +0200 Source: thunderbird Architecture: source Version: 1:128.14.0esr-1 Distribution: unstable Urgency: medium Maintainer: Carsten Schoenert <c.schoenert@t-online.de> Changed-By: Carsten Schoenert <c.schoenert@t-online.de> Changes: thunderbird (1:128.14.0esr-1) unstable; urgency=medium . * [4f3d4b8] New upstream version 128.14.0esr Fixed CVE issues in upstream version 128.14 (MFSA 2025-71): CVE-2025-9179: Sandbox escape due to invalid pointer in the Audio/Video: GMP component CVE-2025-9180: Same-origin policy bypass in the Graphics: Canvas2D component CVE-2025-9181: Uninitialized memory in the JavaScript Engine component CVE-2025-9185: Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142 Checksums-Sha1: a7a2cbe586f5f9cd77560352f7f099f324c5d921 8485 thunderbird_128.14.0esr-1.dsc fb1a49e94f8a9e46d0649e2cb5525386a8833010 13257212 thunderbird_128.14.0esr.orig-thunderbird-l10n.tar.xz 871ac68be2033b2ca31d6b9a67b324b0fd90903c 698720484 thunderbird_128.14.0esr.orig.tar.xz b74c23c145214aef8ee470beec602b13c094a4a3 548900 thunderbird_128.14.0esr-1.debian.tar.xz 8b1babf60c783fcc672a5f77cd0b953858fe5411 40485 thunderbird_128.14.0esr-1_amd64.buildinfo Checksums-Sha256: 881e18dd07a90dddda003bf86fe85015e9d6c06da70904b597e5d226aa08bde2 8485 thunderbird_128.14.0esr-1.dsc 5018a2f359f56ff0519d379269090a051448235e0d927912d0dcba9b3526399d 13257212 thunderbird_128.14.0esr.orig-thunderbird-l10n.tar.xz 56de4d320ffe47e1ea06f2188dc0faa6acadc41fc1eaf64225a67e80c64ea63c 698720484 thunderbird_128.14.0esr.orig.tar.xz 65ddfcae80e3db954db29babb0214daa8bffcefcb72a3468bcb4ee00e0e47740 548900 thunderbird_128.14.0esr-1.debian.tar.xz 4a481ac4dbbddf66d3e6e613fca5259b2265a66a288b0da8c565e1d119ddf45d 40485 thunderbird_128.14.0esr-1_amd64.buildinfo Files: 28a2dc12692b5a295c8c435fce072bfb 8485 mail optional thunderbird_128.14.0esr-1.dsc 408ee85fcf64f0b0596e1478cb443761 13257212 mail optional thunderbird_128.14.0esr.orig-thunderbird-l10n.tar.xz af1aba51f49bab0876ca56945d480942 698720484 mail optional thunderbird_128.14.0esr.orig.tar.xz 14cbf2d87a22243802df50fb3ec132eb 548900 mail optional thunderbird_128.14.0esr-1.debian.tar.xz 10219362990961ce0a6416f42b674b9a 40485 mail optional thunderbird_128.14.0esr-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAminShUACgkQgwFgFCUd HbDc0w//aczv0RLNiRygoWcZPqeBxuFSPwESQYPVY7pkFF6uypNku4Y71ds3ueBX NjskxzKo0hL9MZsAVOhr0rC+nkGpNBtVfXHbZ/X85/vJreiLGynxAokGMCROuZbq fkBjlmD8T3Z3AXesy7JKxOObzzuds4sLe0mrIZqrZmSbPq5BGeBzHAQRUQOgZXF8 awQgEcFdjLf0JKtd7BdzWoOwjFiuDux6sFQaVd/tMCU+t3R9kjIObuC1nTytbyL7 xUX7HqprOPGDJRKMpsk4NnigQgQAVQ86NGA/dRZH+RgtMdNNfz19LpcLa+0hVvuQ PtH3EoGq83jD5fI9Yp34SMmwHG+59JtJHK7oG/ToSNtZ+01otOGg7U55SbkutyCU 0en6JeNH8VxuX6nHBvEuvA4gBltP3BMcw581zaufb0mMU2xieyoqCvUtcVhANZ8/ lTNzKYTODfGhg3a9X3gUg0YJQLckhfoaoNXiCrRHDk64rJ3vq81Lg02kcOJvzGCR UDAIJFgqceIfqjwuyOtSNfGeXD/vTXNeixVGfKmqWSjLWqz9NaBlO5zQNOEjlAJ+ moSOEQQBfcgsZg03jH5RYWoEgQvNs4KP/FfNWh8Qzym6XvWiRH8FXwQaSC41oUAf kgXz6lzxi0ZIi+5lrBppZIJewkWFWlp9CGBzm8EmG95iipXomZQ= =NUev -----END PGP SIGNATURE-----
Attachment:
pgpdD56Pwvpq3.pgp
Description: PGP signature