-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 10 Jan 2020 18:33:43 +0100 Source: thunderbird Architecture: source Version: 1:68.4.1-1 Distribution: unstable Urgency: medium Maintainer: Carsten Schoenert <c.schoen...@t-online.de> Changed-By: Carsten Schoenert <c.schoen...@t-online.de> Changes: thunderbird (1:68.4.1-1) unstable; urgency=medium . * [a00f3e9] New upstream version 68.4.1 Fixed CVE issues in upstream version 68.4.1 (MFSA 2020-04): CVE-2019-17026: IonMonkey type confusion with StoreElementHole and FallibleStoreElement CVE-2019-17015: Memory corruption in parent process during new content process initialization on Windows CVE-2019-17016: Bypass of @namespace CSS sanitization during pasting CVE-2019-17017: Type Confusion in XPCVariant.cpp CVE-2019-17022: CSS sanitization does not escape HTML tags CVE-2019-17024: Memory safety bugs fixed in Thunderbird 68.4.1 * [6b1fd82] rebuild patch queue from patch-queue branch removed patch (included upstream) fixes/Update-bindgen-in-ESR68.-r-glandium-a-RyanVM.patch Checksums-Sha1: 4376dca818e22b9e2a318a02bae79079f6131aeb 8274 thunderbird_68.4.1-1.dsc 4569c0537243f5a46b047fe3e9d9dffd0b9478c4 1045640 thunderbird_68.4.1.orig-lightning-l10n.tar.xz a9a12480310d25267868765f5c7616f10235479e 9835800 thunderbird_68.4.1.orig-thunderbird-l10n.tar.xz ea22af40ce9234f1df54787aa17a3f444d3d107b 357104560 thunderbird_68.4.1.orig.tar.xz 55c6a850a28d72cafff59150f03c328e4e495f8c 545976 thunderbird_68.4.1-1.debian.tar.xz e1a2ddc978402c154c9bd58545571ff4a69cc219 35226 thunderbird_68.4.1-1_amd64.buildinfo Checksums-Sha256: 2f3c32df24ee63380ee099b7886baef0b35213f9ebbb190d5beb9951f0ad6754 8274 thunderbird_68.4.1-1.dsc 479de7baa8e3ad451540db2a77af3b06c80cf953daa87d0219eb790c7a335b63 1045640 thunderbird_68.4.1.orig-lightning-l10n.tar.xz b4373fa07db3080164f571a8513ccbe7d585a070cb99da7b96ad6115fe6a5b90 9835800 thunderbird_68.4.1.orig-thunderbird-l10n.tar.xz 3844d4dfa4135ad382b321cd24f8d283e4bb906df7b2cbdcc5e722f4fbcb96ba 357104560 thunderbird_68.4.1.orig.tar.xz 1d35b07c3e56bb97a954eadae0b481249698e3ffe720ce1dc595534b923cff5d 545976 thunderbird_68.4.1-1.debian.tar.xz 2e08cb5643307772d74b7de5084321cea641b209a460b516c279f323a2a5e5c5 35226 thunderbird_68.4.1-1_amd64.buildinfo Files: 56988e7070a055b45d5bcc33b50148f0 8274 mail optional thunderbird_68.4.1-1.dsc 44ef9e3ef070ff19ded69c8e679a7a41 1045640 mail optional thunderbird_68.4.1.orig-lightning-l10n.tar.xz cbefbc6da1728fe927136ee8865482e3 9835800 mail optional thunderbird_68.4.1.orig-thunderbird-l10n.tar.xz 193cfaacaacb5a0d87f44bc87515080e 357104560 mail optional thunderbird_68.4.1.orig.tar.xz 77f830da06f872e3d86acf3dc77db93a 545976 mail optional thunderbird_68.4.1-1.debian.tar.xz 088ceb08fdc93ee94f39661cb884eb3e 35226 mail optional thunderbird_68.4.1-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAl4ZvJAACgkQgwFgFCUd HbCY4Q/+IMGF7Bvq2j+tlrUHadCn0yy+tp2CgiSWFPT/jW7LO9OqEn4+5D+7nWzb loz0QcXY+eWAj3w/CTvktYOEJ+0AQwusdGNQP3sWz326zFct13ImoCjH8nzY5H/y JnI8vEUIOH9Lq0zHUCKVrxF/hP5qmDKDcH94ofo2HcJ/sWQc6yJSftZVr3JNyQF6 zoWZMUq/SCiKbzIiusQMW7WvVUI+GXPGjpNJyMENlw83krPAAn25JqBajTcwD8X1 mPWEyAiS5bMNGG7+4iIXO8+B05Fz4K8ieyl/9v/97kmdznAohqrIRhM3yYYKvwNs 1tKNdn/PndL5md1YaRgrxNbobObcIl0FEF2OVgYIzjP6NwpSL9R40kxTa9t3p/G9 Y83nzy+/gbHOXknX94oqLQUY5nYB0pB6bQY3qmV2Xj9AYehgZJr1AJUn1ZnH2x5m HVnMCwdedYyIs4HZkFmOLhgKDK57NCiINrbQvP3c+0QDN2EOoywkDl4H3QX2EJyX ICYXx7tbcqqHSByz1ETWYQcXAXWxFZBLaTpnxtIZkNCcxmZa4Y5sfRGI3JTBqnH5 ApT1X82xLWY6eVWH5Gj18fq0aMlz3HDi2DeQYdI2EamI1+2KsivNhN0AkwPArU/o HYzilkxWEksFi4f/Hc0H1CSY33pEoI/dBsWcPqKn6vLETTKqZhc= =02ki -----END PGP SIGNATURE-----