[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 4636-1] thunderbird security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4636-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/               Emilio Pozuelo Monfort
June 19, 2026                                 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : thunderbird
Version        : 1:140.12.0esr-1~deb11u1 1:140.12.0esr-1~deb12u1
CVE ID         : CVE-2026-12289 CVE-2026-12290 CVE-2026-12291 CVE-2026-12292
                 CVE-2026-12294 CVE-2026-12295 CVE-2026-12296 CVE-2026-12297
                 CVE-2026-12298 CVE-2026-12299 CVE-2026-12302 CVE-2026-12304
                 CVE-2026-12305 CVE-2026-12306 CVE-2026-12307 CVE-2026-12308
                 CVE-2026-12309 CVE-2026-12310 CVE-2026-12311 CVE-2026-12312
                 CVE-2026-12313 CVE-2026-12314 CVE-2026-12315 CVE-2026-12324
                 CVE-2026-12325 CVE-2026-12327 CVE-2026-12328 CVE-2026-12329
                 CVE-2026-12330

Multiple security issues were discovered in Thunderbird, which could
result in the execution of arbitrary code.

For Debian 11 bullseye, these problems have been fixed in version
1:140.12.0esr-1~deb11u1.

For Debian 12 bookworm, these problems have been fixed in version
1:140.12.0esr-1~deb12u1.

We recommend that you upgrade your thunderbird packages.

For the detailed security status of thunderbird please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/thunderbird

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAmo1Ai0ACgkQnUbEiOQ2
gwJYaQ/9EHuV66tOEZ0dAXZSFCL0q3L/Ey6cfi0erlVCbPayb7xHitq5kaWQ6Ok2
XEbW6dS9gqGDxMaSi2j2Ojdq3h9Y3fiGdgbF0eJN0ySx2JBCBOBc0FaGYJcrDPTj
LjNO/AKAOgEuY92inHPL2FGKUO63mlr/k+q1GURR6gTJidEStGaQiGDaEBgRu15D
+7hSu6JT2KBrcTKmg0lf6IuM21lyBnUfxhX3mPqOV0EjynjnGQpoktSXi6hk0Wvo
R2ERILI8r0nPyA99/qwH5q+9ttNQ0oC/irePB2taQwKszeyfYsnwloyny7YTd2o+
KXfKWI8YgSO5AkOCHlGvLDFe77uTPTE0y5CnvP/Kh6FAM2sdMht61m5aq22sDlSx
V8NSx9hNhESfGcSqiqL2Ub/1k6LONnyV46HDTqBT24GNxwoulyj6XyE4AsfDoSXy
smFzgDo+czmjtrDF+IhOzquX54wV5vOwmwUm91EQZ5CvRlYbMlV/KkTg9DGkLMYD
FUePksGJ5qSWcDSMG6tLrxwabumkX1kf+PzTpC8PGOa6mmqeQoASPxjrBGGQMtii
T8MgPSk5pRtcCrjhe0tV65cQ5+x6CMHMOnVEn7ezYSqqwrzJ09Y7n7oR654Gjrkr
K9lP9fsrazfm+dlwt8rfbaCeRk9CP54TK2Pe7LLeW/BuaG4i+So=
=q6Fb
-----END PGP SIGNATURE-----


Reply to: