Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package MozillaThunderbird for 
openSUSE:Factory checked in at 2026-07-23 23:13:56
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/MozillaThunderbird (Old)
 and      /work/SRC/openSUSE:Factory/.MozillaThunderbird.new.2004 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "MozillaThunderbird"

Thu Jul 23 23:13:56 2026 rev:391 rq:1367364 version:140.13.0

Changes:
--------
--- /work/SRC/openSUSE:Factory/MozillaThunderbird/MozillaThunderbird.changes    
2026-07-01 16:39:56.055944954 +0200
+++ 
/work/SRC/openSUSE:Factory/.MozillaThunderbird.new.2004/MozillaThunderbird.changes
  2026-07-23 23:15:49.415829601 +0200
@@ -1,0 +2,99 @@
+Tue Jul 21 13:42:04 UTC 2026 - Wolfgang Rosenauer <[email protected]>
+
+- Mozilla Thunderbird 140.13.0 ESR
+  MFSA 2026-72 (bsc#1271649)
+  * CVE-2026-14899 (bmo#2046137)
+    Off-by-one out of bounds read in MIME header parser for forwarding
+  * CVE-2026-15718 (bmo#2045443)
+    Invalid pointer in the JavaScript: WebAssembly component
+  * CVE-2026-15719 (bmo#2043820)
+    Site isolation issue in the DOM: Navigation component
+  * CVE-2026-16349 (bmo#2034682)
+    Same-origin policy bypass in the DOM: Navigation component
+  * CVE-2026-16350 (bmo#2042033)
+    Incorrect boundary conditions in the Audio/Video: cubeb component
+  * CVE-2026-16362 (bmo#2043188)
+    Use-after-free in the WebRTC: Audio/Video component
+  * CVE-2026-16351 (bmo#2045468)
+    Sandbox escape due to use-after-free in the DOM: Navigation component
+  * CVE-2026-16352 (bmo#2046416)
+    Sandbox escape due to use-after-free in the Disability Access
+    APIs component
+  * CVE-2026-16363 (bmo#2047689)
+    JIT miscompilation in the JavaScript: WebAssembly component
+  * CVE-2026-16353 (bmo#2049523)
+    Invalid pointer in the DOM: Bindings (WebIDL) component
+  * CVE-2026-16354 (bmo#2050626)
+    Information disclosure in the Graphics: ImageLib component
+  * CVE-2026-16368 (bmo#2051015)
+    Incorrect boundary conditions in the JavaScript: WebAssembly component
+  * CVE-2026-16369 (bmo#2051854)
+    Integer overflow in the JavaScript: WebAssembly component
+  * CVE-2026-16355 (bmo#2052207)
+    JIT miscompilation in the JavaScript Engine: JIT component
+  * CVE-2026-16356 (bmo#2052562)
+    Sandbox escape due to use-after-free in the Disability Access
+    APIs component
+  * CVE-2026-16357 (bmo#2053326)
+    Incorrect boundary conditions in the Graphics component
+  * CVE-2026-16371 (bmo#2008369)
+    Privilege escalation in the DOM: Navigation component
+  * CVE-2026-16374 (bmo#2027519)
+    Information disclosure in the Framework component in DevTools
+  * CVE-2026-16375 (bmo#2032140)
+    Site isolation issue in the Networking: HTTP component
+  * CVE-2026-16377 (bmo#2037770)
+    Mitigation bypass in the PDF Viewer component
+  * CVE-2026-16379 (bmo#2039452)
+    Privilege escalation in the DOM: Content Processes component
+  * CVE-2026-16358 (bmo#2040119)
+    Site isolation issue in the Graphics: WebRender component
+  * CVE-2026-16381 (bmo#2041001)
+    Same-origin policy bypass in the Networking: DNS component
+  * CVE-2026-16383 (bmo#2041902)
+    Mitigation bypass in the DOM: Networking component
+  * CVE-2026-16387 (bmo#2043200)
+    Site isolation issue in the Networking component
+  * CVE-2026-16390 (bmo#2044527)
+    Mitigation bypass in the Enterprise Policies component
+  * CVE-2026-16391 (bmo#2044536)
+    Information disclosure in the Storage: IndexedDB component
+  * CVE-2026-16359 (bmo#2045424)
+    Incorrect boundary conditions in the Audio/Video: GMP component
+  * CVE-2026-16396 (bmo#2047240)
+    Privilege escalation in WebExtensions
+  * CVE-2026-16405 (bmo#2036591)
+    Information disclosure in the Networking: WebSockets component
+  * CVE-2026-16412 (bmo#2005113, bmo#2025369, bmo#2026301, bmo#2028663,
+    bmo#2029761, bmo#2042242, bmo#2043035, bmo#2043271, bmo#2043300,
+    bmo#2044612, bmo#2045057, bmo#2045187, bmo#2045378, bmo#2045402,
+    bmo#2045406, bmo#2045407, bmo#2045413, bmo#2045417, bmo#2045482,
+    bmo#2045611, bmo#2045616, bmo#2045618, bmo#2045626, bmo#2045730,
+    bmo#2045732, bmo#2045756, bmo#2045769, bmo#2045771, bmo#2046917,
+    bmo#2047718, bmo#2047957, bmo#2048934, bmo#2049818, bmo#2049822,
+    bmo#2050151, bmo#2050368, bmo#2051653, bmo#2051658, bmo#2053635,
+    bmo#2053637)
+    Memory safety bugs fixed in Thunderbird ESR 140.13 and
+    Thunderbird 153
+  * CVE-2026-16360 (bmo#2022635, bmo#2028004, bmo#2035756, bmo#2043739,
+    bmo#2045184, bmo#2045185, bmo#2045198, bmo#2045281, bmo#2045392,
+    bmo#2045395, bmo#2045396, bmo#2045397, bmo#2045405, bmo#2045414,
+    bmo#2045415, bmo#2045451, bmo#2045454, bmo#2045508, bmo#2045510,
+    bmo#2045513, bmo#2045515, bmo#2045518, bmo#2045604, bmo#2045607,
+    bmo#2045612, bmo#2045614, bmo#2045617, bmo#2045619, bmo#2045624,
+    bmo#2045625, bmo#2045729, bmo#2045737, bmo#2045741, bmo#2045742,
+    bmo#2045744, bmo#2045763, bmo#2045767, bmo#2045770, bmo#2045772,
+    bmo#2045773, bmo#2045775, bmo#2045783, bmo#2045833, bmo#2045848,
+    bmo#2045865, bmo#2045875, bmo#2045957, bmo#2047719, bmo#2047723,
+    bmo#2047729, bmo#2048795, bmo#2048799, bmo#2048801, bmo#2049392,
+    bmo#2049397, bmo#2049398, bmo#2049399, bmo#2049404, bmo#2049405,
+    bmo#2049407, bmo#2049805, bmo#2049812, bmo#2050657, bmo#2050668,
+    bmo#2050990, bmo#2051666, bmo#2053166, bmo#2053273, bmo#2053576,
+    bmo#2053583, bmo#2053587)
+    Memory safety bugs fixed in Thunderbird ESR 140.13 and
+    Thunderbird 153
+  * CVE-2026-16361 (bmo#2029734, bmo#2036518)
+    Memory safety bugs fixed in Thunderbird ESR 140.13
+- require transitional rust-cbindgen-0_29_<F2> package to build
+
+-------------------------------------------------------------------

Old:
----
  l10n-140.12.1esr.tar.xz
  thunderbird-140.12.1esr.source.tar.xz
  thunderbird-140.12.1esr.source.tar.xz.asc

New:
----
  l10n-140.13.0esr.tar.xz
  thunderbird-140.13.0esr.source.tar.xz
  thunderbird-140.13.0esr.source.tar.xz.asc

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ MozillaThunderbird.spec ++++++
--- /var/tmp/diff_new_pack.67liIZ/_old  2026-07-23 23:16:22.492991266 +0200
+++ /var/tmp/diff_new_pack.67liIZ/_new  2026-07-23 23:16:22.496991407 +0200
@@ -30,8 +30,8 @@
 # major 69
 # mainver %%major.99
 %define major          140
-%define mainver        %major.12.1
-%define orig_version   140.12.1
+%define mainver        %major.13.0
+%define orig_version   140.13.0
 %define orig_suffix    esr
 %define update_channel esr
 %define source_prefix  thunderbird-%{orig_version}
@@ -136,7 +136,7 @@
 BuildRequires:  python3-devel
 %endif
 %endif
-BuildRequires:  rust-cbindgen >= 0.27
+BuildRequires:  rust-cbindgen-0_29_2
 BuildRequires:  translate-suse-desktop
 BuildRequires:  unzip
 BuildRequires:  xorg-x11-libXt-devel

++++++ l10n-140.12.1esr.tar.xz -> l10n-140.13.0esr.tar.xz ++++++

++++++ tar_stamps ++++++
--- /var/tmp/diff_new_pack.67liIZ/_old  2026-07-23 23:16:22.801002038 +0200
+++ /var/tmp/diff_new_pack.67liIZ/_new  2026-07-23 23:16:22.809002317 +0200
@@ -1,11 +1,11 @@
 PRODUCT="thunderbird"
 CHANNEL="esr140"
-VERSION="140.12.1"
+VERSION="140.13.0"
 VERSION_SUFFIX="esr"
-REV_VERSION="140.12.0"
+REV_VERSION="140.12.1"
 PREV_VERSION_SUFFIX="esr"
 #SKIP_LOCALES="" # Uncomment to skip l10n and compare-locales-generation
 RELEASE_REPO="https://hg.mozilla.org/releases/comm-esr140";
-RELEASE_TAG="13d851e90bd757b9432a16a9766610b28bf5c3e1"
-RELEASE_TIMESTAMP="20260628021646"
+RELEASE_TAG="faf78db7dfb184002adc6b859c8ad395ff216239"
+RELEASE_TIMESTAMP="20260721190809"
 

++++++ thunderbird-140.12.1esr.source.tar.xz -> 
thunderbird-140.13.0esr.source.tar.xz ++++++
/work/SRC/openSUSE:Factory/MozillaThunderbird/thunderbird-140.12.1esr.source.tar.xz
 
/work/SRC/openSUSE:Factory/.MozillaThunderbird.new.2004/thunderbird-140.13.0esr.source.tar.xz
 differ: char 15, line 1

Reply via email to