Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package MozillaThunderbird for openSUSE:Factory checked in at 2026-09-04 12:39:52 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/MozillaThunderbird (Old) and /work/SRC/openSUSE:Factory/.MozillaThunderbird.new.1265 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "MozillaThunderbird" Fri Sep 4 12:39:52 2026 rev:393 rq:1375538 version:140.15.0 Changes: -------- --- /work/SRC/openSUSE:Factory/MozillaThunderbird/MozillaThunderbird.changes 2026-08-20 16:15:47.161290650 +0200 +++ /work/SRC/openSUSE:Factory/.MozillaThunderbird.new.1265/MozillaThunderbird.changes 2026-09-04 12:40:30.934806859 +0200 @@ -1,0 +2,48 @@ +Sun Aug 30 10:25:54 UTC 2026 - Wolfgang Rosenauer <[email protected]> + +- Mozilla Thunderbird 140.15.0 ESR + https://www.thunderbird.net/en-US/thunderbird/140.15.0esr/releasenotes/ + * Windows jump list menu no longer functioned correctly + MFSA 2026-87 (bsc#1278001) + * CVE-2026-84639 (bmo#2061087) + Uninitialized memory in MIME parsing + * CVE-2026-84640 (bmo#2063964) + One byte overflow read in mail parser + * CVE-2026-84641 (bmo#2057805) + Information disclosure due to malicious IMAP server response + * CVE-2026-75874 (bmo#2039972) + Sandbox escape in the Remote Settings Client component + * CVE-2026-16365 (bmo#2049149) + Privilege escalation in the DOM: Workers component + * CVE-2026-84119 (bmo#2057817) + Sandbox escape due to use-after-free in the DOM: Navigation component + * CVE-2026-84120 (bmo#2058911) + Use-after-free in the Audio/Video component + * CVE-2026-84121 (bmo#2059018) + Sandbox escape due to use-after-free in the DOM: Security component + * CVE-2026-84122 (bmo#2059965) + Use-after-free in the Audio/Video component + * CVE-2026-84124 (bmo#2061110) + Use-after-free in the DOM: Core & HTML component + * CVE-2026-16371 (bmo#2008369) + Privilege escalation in the DOM: Navigation component + * CVE-2026-84131 (bmo#2060008) + Privilege escalation due to invalid pointer in the Graphics component + * CVE-2026-84143 (bmo#2048793, bmo#2054631, bmo#2054645, bmo#2054657, + bmo#2055007, bmo#2055681, bmo#2057107, bmo#2057108, bmo#2057114, + bmo#2058087, bmo#2058088, bmo#2058090, bmo#2058095, bmo#2058101, + bmo#2059109, bmo#2059183, bmo#2059185, bmo#2061287, bmo#2061301, + bmo#2061325) + Internally found bugs fixed in Thunderbird 155, Thunderbird + ESR 153.2 and Thunderbird ESR 140.15 + * CVE-2026-84145 (bmo#2054640, bmo#2054650, bmo#2054652, bmo#2055678, + bmo#2055693, bmo#2055705, bmo#2058001, bmo#2058051, bmo#2058652, + bmo#2058660, bmo#2059027, bmo#2059139, bmo#2061220, bmo#2061242, + bmo#2061285, bmo#2061300, bmo#2061316, bmo#2061397, bmo#2062400, + bmo#2062419) + Internally found bugs fixed in Thunderbird 155, Thunderbird + ESR 153.2 and Thunderbird ESR 140.15 +- Mozilla Thunderbird 140.14.1 ESR + * Dragging attachments from Local Folders to desktop failed on Windows + +------------------------------------------------------------------- Old: ---- l10n-140.14.0esr.tar.xz thunderbird-140.14.0esr.source.tar.xz thunderbird-140.14.0esr.source.tar.xz.asc New: ---- l10n-140.15.0esr.tar.xz thunderbird-140.15.0esr.source.tar.xz thunderbird-140.15.0esr.source.tar.xz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ MozillaThunderbird.spec ++++++ --- /var/tmp/diff_new_pack.l8zutF/_old 2026-09-04 12:41:15.757380880 +0200 +++ /var/tmp/diff_new_pack.l8zutF/_new 2026-09-04 12:41:15.761381021 +0200 @@ -30,8 +30,8 @@ # major 69 # mainver %%major.99 %define major 140 -%define mainver %major.14.0 -%define orig_version 140.14.0 +%define mainver %major.15.0 +%define orig_version 140.15.0 %define orig_suffix esr %define update_channel esr %define source_prefix thunderbird-%{orig_version} ++++++ l10n-140.14.0esr.tar.xz -> l10n-140.15.0esr.tar.xz ++++++ ++++++ tar_stamps ++++++ --- /var/tmp/diff_new_pack.l8zutF/_old 2026-09-04 12:41:16.312400371 +0200 +++ /var/tmp/diff_new_pack.l8zutF/_new 2026-09-04 12:41:16.321400687 +0200 @@ -1,11 +1,11 @@ PRODUCT="thunderbird" CHANNEL="esr140" -VERSION="140.14.0" +VERSION="140.15.0" VERSION_SUFFIX="esr" -REV_VERSION="140.13.0" +REV_VERSION="140.14.1" PREV_VERSION_SUFFIX="esr" #SKIP_LOCALES="" # Uncomment to skip l10n and compare-locales-generation RELEASE_REPO="https://hg.mozilla.org/releases/comm-esr140" -RELEASE_TAG="01ada2b85d92111c65b34af0364dc860d3f8e04b" -RELEASE_TIMESTAMP="20260817220353" +RELEASE_TAG="07b07d600bccd509bdf75bad761310fd95cc928d" +RELEASE_TIMESTAMP="20260828005046" ++++++ thunderbird-140.14.0esr.source.tar.xz -> thunderbird-140.15.0esr.source.tar.xz ++++++ /work/SRC/openSUSE:Factory/MozillaThunderbird/thunderbird-140.14.0esr.source.tar.xz /work/SRC/openSUSE:Factory/.MozillaThunderbird.new.1265/thunderbird-140.15.0esr.source.tar.xz differ: char 15, line 1
