Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package MozillaThunderbird for openSUSE:Factory checked in at 2022-06-01 17:34:24 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/MozillaThunderbird (Old) and /work/SRC/openSUSE:Factory/.MozillaThunderbird.new.1548 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "MozillaThunderbird" Wed Jun 1 17:34:24 2022 rev:281 rq:980158 version:91.10.0 Changes: -------- --- /work/SRC/openSUSE:Factory/MozillaThunderbird/MozillaThunderbird.changes 2022-05-23 15:51:32.158634521 +0200 +++ /work/SRC/openSUSE:Factory/.MozillaThunderbird.new.1548/MozillaThunderbird.changes 2022-06-01 17:34:43.690745492 +0200 @@ -1,0 +2,30 @@ +Thu May 26 07:56:09 UTC 2022 - Wolfgang Rosenauer <w...@rosenauer.org> + +- Mozilla Thunderbird 91.10.0 + * Various UX and theme improvements + MFSA 2022-22 (bsc#1200027) + * CVE-2022-31736 (bmo#1735923) + Cross-Origin resource's length leaked + * CVE-2022-31737 (bmo#1743767) + Heap buffer overflow in WebGL + * CVE-2022-31738 (bmo#1756388) + Browser window spoof using fullscreen mode + * CVE-2022-31739 (bmo#1765049) + Attacker-influenced path traversal when saving downloaded + files + * CVE-2022-31740 (bmo#1766806) + Register allocation problem in WASM on arm64 + * CVE-2022-31741 (bmo#1767590) + Uninitialized variable leads to invalid memory read + * CVE-2022-1834 (bmo#1767816) + Braille space character caused incorrect sender email to be + shown for a digitally signed email + * CVE-2022-31742 (bmo#1730434) + Querying a WebAuthn token with a large number of + allowCredential entries may have leaked cross-origin + information + * CVE-2022-31747 (bmo#1760765, bmo#1765610, bmo#1766283, + bmo#1767365, bmo#1768559, bmo#1768734) + Memory safety bugs fixed in Thunderbird 91.10 + +------------------------------------------------------------------- Old: ---- l10n-91.9.1.tar.xz thunderbird-91.9.1.source.tar.xz thunderbird-91.9.1.source.tar.xz.asc New: ---- l10n-91.10.0.tar.xz thunderbird-91.10.0.source.tar.xz thunderbird-91.10.0.source.tar.xz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ MozillaThunderbird.spec ++++++ --- /var/tmp/diff_new_pack.UYunBg/_old 2022-06-01 17:34:52.946756428 +0200 +++ /var/tmp/diff_new_pack.UYunBg/_new 2022-06-01 17:34:52.950756433 +0200 @@ -29,8 +29,8 @@ # major 69 # mainver %major.99 %define major 91 -%define mainver %major.9.1 -%define orig_version 91.9.1 +%define mainver %major.10.0 +%define orig_version 91.10.0 %define orig_suffix %{nil} %define update_channel release %define source_prefix thunderbird-%{orig_version} @@ -105,7 +105,7 @@ BuildRequires: libXcomposite-devel BuildRequires: libcurl-devel BuildRequires: mozilla-nspr-devel >= 4.32 -BuildRequires: mozilla-nss-devel >= 3.68 +BuildRequires: mozilla-nss-devel >= 3.68.4 BuildRequires: nasm >= 2.14 BuildRequires: nodejs >= 10.22.1 %if 0%{?sle_version} >= 120000 && 0%{?sle_version} < 150000 ++++++ l10n-91.9.1.tar.xz -> l10n-91.10.0.tar.xz ++++++ ++++++ tar_stamps ++++++ --- /var/tmp/diff_new_pack.UYunBg/_old 2022-06-01 17:34:53.170756694 +0200 +++ /var/tmp/diff_new_pack.UYunBg/_new 2022-06-01 17:34:53.174756698 +0200 @@ -1,8 +1,8 @@ PRODUCT="thunderbird" CHANNEL="esr91" -VERSION="91.9.1" +VERSION="91.10.0" VERSION_SUFFIX="" -PREV_VERSION="91.9.0" +PREV_VERSION="91.9.1" PREV_VERSION_SUFFIX="" #SKIP_LOCALES="" # Uncomment to skip l10n and compare-locales-generation RELEASE_REPO="https://hg.mozilla.org/releases/comm-esr91" ++++++ thunderbird-91.9.1.source.tar.xz -> thunderbird-91.10.0.source.tar.xz ++++++ /work/SRC/openSUSE:Factory/MozillaThunderbird/thunderbird-91.9.1.source.tar.xz /work/SRC/openSUSE:Factory/.MozillaThunderbird.new.1548/thunderbird-91.10.0.source.tar.xz differ: char 15, line 1