-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 15 May 2025 17:54:43 +0200
Source: thunderbird
Architecture: source
Version: 1:128.10.1esr-1
Distribution: unstable
Urgency: medium
Maintainer: Carsten Schoenert <
c.schoenert@t-online.de>
Changed-By: Christoph Goehre <
chris@sigxcpu.org>
Changes:
thunderbird (1:128.10.1esr-1) unstable; urgency=medium
.
* [b31c095] New upstream version 128.10.1esr
Fixed CVE issues in upstream version 128.10.1 (MFSA 2025-34):
CVE-2025-3875: Sender Spoofing via Malformed From Header in Thunderbird
CVE-2025-3877: Unsolicited File Download, Disk Space Exhaustion, and
Credential Leakage via mailbox:/// Links
CVE-2025-3909: JavaScript Execution via Spoofed PDF Attachment and
file:/// Link
CVE-2025-3932: Tracking Links in Attachments Bypassed Remote Content
Blocking
Checksums-Sha1:
7aea9f7e3fb0fa3e3e5404d171ea87e6b604681b 8485 thunderbird_128.10.1esr-1.dsc
c85029117dbc8e664e1a407dd4fcfcfef1c236a7 13221316 thunderbird_128.10.1esr.orig-thunderbird-l10n.tar.xz
6c5407a1bf6169e4fdd43fec4d5574ecbd06b79e 700033616 thunderbird_128.10.1esr.orig.tar.xz
2de68f7904502b5e57cd25ef0b985ed096ccf18d 548244 thunderbird_128.10.1esr-1.debian.tar.xz
bfb88624942099eb2898c8d559045e0178cec3a1 6410 thunderbird_128.10.1esr-1_source.buildinfo
Checksums-Sha256:
bb2c64c5bfd147d919e99c96e5842aa615ba82a6ad27abb48f9679ce71517503 8485 thunderbird_128.10.1esr-1.dsc
6885f408eeb87ef7f1c57fee1a23737ed4f62ff3e183ddd8cf1c558af7c638e8 13221316 thunderbird_128.10.1esr.orig-thunderbird-l10n.tar.xz
aa0cc78f9b7c84c1f2efbc1ee495d1d9495b602acbc8d191605339480991dafc 700033616 thunderbird_128.10.1esr.orig.tar.xz
b233c54088bd4e5b6dc07a65880789a8080bd67a848bb801fee18dcf09d3c6b8 548244 thunderbird_128.10.1esr-1.debian.tar.xz
f1e92469bd0c5899ae98536fe16a5b9925a268f6284b29353e371f3f9fc4ded9 6410 thunderbird_128.10.1esr-1_source.buildinfo
Files:
b3140967563721b8baf178d738f2bf23 8485 mail optional thunderbird_128.10.1esr-1.dsc
54312cca5550b95c6acb8d78ae4563dc 13221316 mail optional thunderbird_128.10.1esr.orig-thunderbird-l10n.tar.xz
16af9b51faac3e434c8c427f72ac87c8 700033616 mail optional thunderbird_128.10.1esr.orig.tar.xz
1a7867c061059cf48b8024fd48734fa8 548244 mail optional thunderbird_128.10.1esr-1.debian.tar.xz
179a5ceb2bcca9822f461052b5d4a6e8 6410 mail optional thunderbird_128.10.1esr-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEi5SBnCVVcKN0tizNJuPIdadEIO8FAmgmKTwACgkQJuPIdadE IO+GdRAAj/e9WNJ+++bQCEGqrIYSsEp0QSi4H59MeNIgxYlPc/vW3bys1+VW3FKs sy3wd5Hausoik+Cebv14oYJ1Ex6dJiFpDjsDslY4tFbMbBs5u0dDH6KeBpmKhE5b nK8SP3mO1mtzgdgkf3RGkEhyP/SyALTPeEWbRuc6L7liYRsiKEF0SKjpknuLPoxT CZVpdKyXMC8wvddQDdpOkrYFZ8G5MLqW9vPQ1ks/ZuFvEWJaPGsr6k6dyTLlyU/n ggjbenAQTneF2uqr5CXYAWH8n5ys7nvSxA6NqrSQTM4Lk5bgu7Tsj5HMQIMxxU99 D2hROWEmS/B7R7eHvmEhfiMliaFa1YAWuH7QwFqRRsedntpp8FInUHBm33/pWfOc pt1VOqHqPX6MjGcrAD7UCEQRik4XQEml4j295+B9/bF0doijSppQ1jjS8P9+xcvu wlLDt65GKwtadkUh/Jap7MHGNKHXbnbQCKcu48Ql8PNyfegejXFh4DMNH2YSyPUo a+Micz1yvMRbF45QG2Q1I87tQqhqHWQkGvyMhrJGgjIiE8mHMSktt2A4WbEedafr XiW/rFZ0Bj8GGxO8gXPxdWoyaf/fvsBspxLqMKqnZqyCPd1PfhC96epZsJRfx8U2 mH11OG+yMPDa94Rhqg5rd9UvYEkXLeeSasCZCO8p93V85i/5ev8=
=XpL0
-----END PGP SIGNATURE-----
--==============11998380415387895=Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCaCY8rgAKCRCb9qggYcy5 ISNEAQCNgQ1fCu0M3+ZeHC+UjJpQIbVtBYOUb1sZw+OyfQZkDAEAv9UkzhX+p1ot a5xHQTc9EDCI3Y6fyRnrizESGJZYJQk=ulZT
-----END PGP SIGNATURE-----
--- SoupGate-Win32 v1.05
* Origin: fsxNet Usenet Gateway (21:1/5)