Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package MozillaThunderbird for
openSUSE:Factory checked in at 2026-09-21 12:02:35
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/MozillaThunderbird (Old)
and /work/SRC/openSUSE:Factory/.MozillaThunderbird.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "MozillaThunderbird"
Mon Sep 21 12:02:35 2026 rev:394 rq:1379126 version:140.16.0
Changes:
--------
--- /work/SRC/openSUSE:Factory/MozillaThunderbird/MozillaThunderbird.changes
2026-09-04 12:40:30.934806859 +0200
+++
/work/SRC/openSUSE:Factory/.MozillaThunderbird.new.383539/MozillaThunderbird.changes
2026-09-21 12:03:11.755180766 +0200
@@ -1,0 +2,78 @@
+Tue Sep 15 07:56:03 UTC 2026 - Wolfgang Rosenauer <[email protected]>
+
+- Mozilla Thunderbird 140.16.0 ESR
+ MFSA 2026-95 (bsc#1280371)
+ * CVE-2026-92238 (bmo#2060601)
+ Ambiguous parsing of mail headers
+ * CVE-2026-92239 (bmo#2060488)
+ Buffer overrun in IMAP
+ * CVE-2026-92240 (bmo#2069113)
+ Out-of-bounds read in IMAP response parser
+ * CVE-2026-92005 (bmo#2056051)
+ Use-after-free in the Audio/Video: Web Codecs component
+ * CVE-2026-92006 (bmo#2057121)
+ Privilege escalation due to incorrect boundary conditions in
+ the Graphics: CanvasWebGL component
+ * CVE-2026-92007 (bmo#2058064)
+ Privilege escalation due to incorrect boundary conditions in
+ the Graphics: CanvasWebGL component
+ * CVE-2026-92008 (bmo#2058065)
+ Privilege escalation due to incorrect boundary conditions in
+ the Graphics: CanvasWebGL component
+ * CVE-2026-92009 (bmo#2058066)
+ Privilege escalation due to incorrect boundary conditions in
+ the Graphics: CanvasWebGL component
+ * CVE-2026-92010 (bmo#2058067)
+ Privilege escalation due to incorrect boundary conditions in
+ the Graphics: CanvasWebGL component
+ * CVE-2026-92011 (bmo#2058068)
+ Privilege escalation due to incorrect boundary conditions in
+ the Graphics: CanvasWebGL component
+ * CVE-2026-92012 (bmo#2058069)
+ Privilege escalation due to incorrect boundary conditions in
+ the Graphics: CanvasWebGL component
+ * CVE-2026-92013 (bmo#2058078)
+ Privilege escalation due to incorrect boundary conditions in
+ the Graphics: CanvasWebGL component
+ * CVE-2026-92014 (bmo#2060000)
+ Privilege escalation due to incorrect boundary conditions in
+ the Graphics component
+ * CVE-2026-92015 (bmo#2060235)
+ Privilege escalation in the WebExtensions component
+ * CVE-2026-92016 (bmo#2061327)
+ Use-after-free in the Disability Access APIs component
+ * CVE-2026-92017 (bmo#2061777)
+ Privilege escalation in the DOM: Service Workers component
+ * CVE-2026-92018 (bmo#2064287)
+ Sandbox escape in the DOM: Core & HTML component
+ * CVE-2026-92019 (bmo#2065636)
+ Mitigation bypass in the Remote Settings Client component
+ * CVE-2026-92020 (bmo#2066329)
+ Privilege escalation due to incorrect boundary conditions in
+ the Graphics: WebRender component
+ * CVE-2026-92021 (bmo#2067208)
+ Use-after-free in the JavaScript Engine: JIT component
+ * CVE-2026-92022 (bmo#2068059)
+ Use-after-free in the DOM: HTML Parser component
+ * CVE-2026-92023 (bmo#2068342)
+ Use-after-free in the XML component
+ * CVE-2026-92024 (bmo#2068354)
+ Use-after-free in the SVG component
+ * CVE-2026-92025 (bmo#2068361)
+ Use-after-free in the DOM: Navigation component
+ * CVE-2026-92026 (bmo#2068378)
+ Use-after-free in the Networking component
+ * CVE-2026-92027 (bmo#2068433)
+ Use-after-free in the DOM: Streams component
+ * CVE-2026-92028 (bmo#2068440)
+ Use-after-free in the DOM: Core & HTML component
+ * CVE-2026-92029 (bmo#2068445)
+ Use-after-free in the SVG component
+ * CVE-2026-92030 (bmo#2058417)
+ Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component
+ * CVE-2026-92031 (bmo#2067971)
+ Information disclosure in the Graphics: ImageLib component
+ * CVE-2026-92032 (bmo#2068437)
+ Sandbox escape due to invalid pointer in the Graphics component
+
+-------------------------------------------------------------------
Old:
----
l10n-140.15.0esr.tar.xz
thunderbird-140.15.0esr.source.tar.xz
thunderbird-140.15.0esr.source.tar.xz.asc
New:
----
l10n-140.16.0esr.tar.xz
thunderbird-140.16.0esr.source.tar.xz
thunderbird-140.16.0esr.source.tar.xz.asc
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ MozillaThunderbird.spec ++++++
--- /var/tmp/diff_new_pack.f4nqLS/_old 2026-09-21 12:03:46.348631604 +0200
+++ /var/tmp/diff_new_pack.f4nqLS/_new 2026-09-21 12:03:46.350631688 +0200
@@ -30,8 +30,8 @@
# major 69
# mainver %%major.99
%define major 140
-%define mainver %major.15.0
-%define orig_version 140.15.0
+%define mainver %major.16.0
+%define orig_version 140.16.0
%define orig_suffix esr
%define update_channel esr
%define source_prefix thunderbird-%{orig_version}
++++++ l10n-140.15.0esr.tar.xz -> l10n-140.16.0esr.tar.xz ++++++
++++++ tar_stamps ++++++
--- /var/tmp/diff_new_pack.f4nqLS/_old 2026-09-21 12:03:46.665644899 +0200
+++ /var/tmp/diff_new_pack.f4nqLS/_new 2026-09-21 12:03:46.670645109 +0200
@@ -1,11 +1,11 @@
PRODUCT="thunderbird"
CHANNEL="esr140"
-VERSION="140.15.0"
+VERSION="140.16.0"
VERSION_SUFFIX="esr"
-REV_VERSION="140.14.1"
+REV_VERSION="140.15.0"
PREV_VERSION_SUFFIX="esr"
#SKIP_LOCALES="" # Uncomment to skip l10n and compare-locales-generation
RELEASE_REPO="https://hg.mozilla.org/releases/comm-esr140"
-RELEASE_TAG="07b07d600bccd509bdf75bad761310fd95cc928d"
-RELEASE_TIMESTAMP="20260828005046"
+RELEASE_TAG="1f72e9240dd91a3091ae87ff358a04a70b20783e"
+RELEASE_TIMESTAMP="20260914195918"
++++++ thunderbird-140.15.0esr.source.tar.xz ->
thunderbird-140.16.0esr.source.tar.xz ++++++
/work/SRC/openSUSE:Factory/MozillaThunderbird/thunderbird-140.15.0esr.source.tar.xz
/work/SRC/openSUSE:Factory/.MozillaThunderbird.new.383539/thunderbird-140.16.0esr.source.tar.xz
differ: char 15, line 1