Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package MozillaThunderbird for openSUSE:Factory checked in at 2025-09-18 21:08:21 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/MozillaThunderbird (Old) and /work/SRC/openSUSE:Factory/.MozillaThunderbird.new.27445 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "MozillaThunderbird" Thu Sep 18 21:08:21 2025 rev:372 rq:1305384 version:140.3.0 Changes: -------- --- /work/SRC/openSUSE:Factory/MozillaThunderbird/MozillaThunderbird.changes 2025-09-16 18:20:06.827428679 +0200 +++ /work/SRC/openSUSE:Factory/.MozillaThunderbird.new.27445/MozillaThunderbird.changes 2025-09-18 21:08:49.814788797 +0200 @@ -1,0 +2,30 @@ +Sun Sep 14 06:58:42 UTC 2025 - Wolfgang Rosenauer <[email protected]> + +- Mozilla Thunderbird 140.3.0 ESR + * Right-clicking 'List-ID' -> 'Unsubscribe' created double encoded + draft subject + * Thunderbird could crash on startup + * Thunderbird could crash when importing mail + * Opening Website header link in RSS feed incorrectly re-encoded + URL parameters + MFSA 2025-78 (bsc#1249391) + * CVE-2025-10527 (bmo#1984825) + Sandbox escape due to use-after-free in the Graphics: + Canvas2D component + * CVE-2025-10528 (bmo#1986185) + Sandbox escape due to undefined behavior, invalid pointer in + the Graphics: Canvas2D component + * CVE-2025-10529 (bmo#1970490) + Same-origin policy bypass in the Layout component + * CVE-2025-10532 (bmo#1979502) + Incorrect boundary conditions in the JavaScript: GC component + * CVE-2025-10533 (bmo#1980788) + Integer overflow in the SVG component + * CVE-2025-10536 (bmo#1981502) + Information disclosure in the Networking: Cache component + * CVE-2025-10537 (bmo#1938220, bmo#1980730, bmo#1981280, + bmo#1981283, bmo#1984505, bmo#1985067) + Memory safety bugs fixed in Firefox ESR 140.3, Thunderbird + ESR 140.3, Firefox 143 and Thunderbird 143 + +------------------------------------------------------------------- Old: ---- l10n-140.2.1esr.tar.xz thunderbird-140.2.1esr.source.tar.xz thunderbird-140.2.1esr.source.tar.xz.asc New: ---- l10n-140.3.0esr.tar.xz thunderbird-140.3.0esr.source.tar.xz thunderbird-140.3.0esr.source.tar.xz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ MozillaThunderbird.spec ++++++ --- /var/tmp/diff_new_pack.XpiU1l/_old 2025-09-18 21:09:07.455530107 +0200 +++ /var/tmp/diff_new_pack.XpiU1l/_new 2025-09-18 21:09:07.487531452 +0200 @@ -30,8 +30,8 @@ # major 69 # mainver %%major.99 %define major 140 -%define mainver %major.2.1 -%define orig_version 140.2.1 +%define mainver %major.3.0 +%define orig_version 140.3.0 %define orig_suffix esr %define update_channel esr %define source_prefix thunderbird-%{orig_version} ++++++ l10n-140.2.1esr.tar.xz -> l10n-140.3.0esr.tar.xz ++++++ /work/SRC/openSUSE:Factory/MozillaThunderbird/l10n-140.2.1esr.tar.xz /work/SRC/openSUSE:Factory/.MozillaThunderbird.new.27445/l10n-140.3.0esr.tar.xz differ: char 15, line 1 ++++++ tar_stamps ++++++ --- /var/tmp/diff_new_pack.XpiU1l/_old 2025-09-18 21:09:08.363568261 +0200 +++ /var/tmp/diff_new_pack.XpiU1l/_new 2025-09-18 21:09:08.367568430 +0200 @@ -1,11 +1,11 @@ PRODUCT="thunderbird" CHANNEL="esr140" -VERSION="140.2.1" +VERSION="140.3.0" VERSION_SUFFIX="esr" -REV_VERSION="140.2.0" +REV_VERSION="140.2.1" PREV_VERSION_SUFFIX="esr" #SKIP_LOCALES="" # Uncomment to skip l10n and compare-locales-generation RELEASE_REPO="https://hg.mozilla.org/releases/comm-esr140" -RELEASE_TAG="5df036ddfe367ff4452a4aa6235bb652dca89fa4" -RELEASE_TIMESTAMP="20250828033206" +RELEASE_TAG="34b243658c31506d293b13d67238ccca56c290e0" +RELEASE_TIMESTAMP="20250911182516" ++++++ thunderbird-140.2.1esr.source.tar.xz -> thunderbird-140.3.0esr.source.tar.xz ++++++ /work/SRC/openSUSE:Factory/MozillaThunderbird/thunderbird-140.2.1esr.source.tar.xz /work/SRC/openSUSE:Factory/.MozillaThunderbird.new.27445/thunderbird-140.3.0esr.source.tar.xz differ: char 15, line 1
