[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#991236: marked as done (unblock: thunderbird/1:78.12.0-1)



Your message dated Sun, 18 Jul 2021 10:22:42 +0200
with message-id <CAM8zJQtVpqHQUhAkys0hJhhj8ZaNqdQTv6DAwT5=Q+CvsNAirA@mail.gmail.com>
and subject line Re: Bug#991236: unblock: thunderbird/1:78.12.0-1
has caused the Debian Bug report #991236,
regarding unblock: thunderbird/1:78.12.0-1
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
991236: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=991236
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: release.debian.org
Severity: normal
User: release.debian.org@packages.debian.org
Usertags: unblock

Please unblock package thunderbird

There was again a new ESR release of Thunderbird which fixes as usual
some CVEs.

[ Reason ]
These CVEs got fixed by upstream release of 78.11.0 and 78.12.0.
CVE-2021-29969: IMAP server responses sent by a MITM prior to STARTTLS
                could be processed
CVE-2021-29970: Use-after-free in accessibility features of a document
CVE-2021-30547: Out of bounds write in ANGLE
CVE-2021-29976: Memory safety bugs fixed in Thunderbird 78.12

[ Impact ]
Users of testing will get excluded from using the newer version with the
fixed CVE related issues.

[ Tests ]
The local usage and installation tests didn't have shown any anomalies,
the autopkgtests did run also successful.

[ Risks ]
The same risks are given as in the unblock request for 78.11.0-1, but
contrary to 78.11.0-1 and the libnss3 library issue, which was worked
around by -2 no other new issues come up until then. Thus I expect
really no new bug reports due the new bumped version of Thunderbird.

The upload of 78.12.0-1 to unstable did happen yesterday, even if the
new Thunderbird version was released on Tuesday in the past week as I was
offline for a few days due the various flood catastrophes near my home.

You might want to decerase the transition time really only to a few days
so we can act quick enough in case some issues will come up.

[ Checklist ]
  [x] all changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [ ] attach debdiff against the package in testing

[ Other info ]
Again I'm not attaching a debdiff as even a smaller set of upstream
modifications did happen it would be rather big and time consuming to
read.

unblock thunderbird/1:78.12.0-1

--- End Message ---
--- Begin Message ---
Unblocked.

--- End Message ---

Reply to: