Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package MozillaThunderbird for openSUSE:Factory checked in at 2023-08-03 17:29:27 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/MozillaThunderbird (Old) and /work/SRC/openSUSE:Factory/.MozillaThunderbird.new.22712 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "MozillaThunderbird" Thu Aug 3 17:29:27 2023 rev:314 rq:1102113 version:102.14.0 Changes: -------- --- /work/SRC/openSUSE:Factory/MozillaThunderbird/MozillaThunderbird.changes 2023-07-26 13:25:47.700669930 +0200 +++ /work/SRC/openSUSE:Factory/.MozillaThunderbird.new.22712/MozillaThunderbird.changes 2023-08-03 17:29:28.595652087 +0200 @@ -1,0 +2,26 @@ +Tue Aug 1 20:15:02 UTC 2023 - Wolfgang Rosenauer <w...@rosenauer.org> + +- Mozilla Thunderbird 102.14.0 + MFSA 2023-32 (bsc#1213746) + * CVE-2023-4045 (bmo#1833876) + Offscreen Canvas could have bypassed cross-origin restrictions + * CVE-2023-4046 (bmo#1837686) + Incorrect value used during WASM compilation + * CVE-2023-4047 (bmo#1839073) + Potential permissions request bypass via clickjacking + * CVE-2023-4048 (bmo#1841368) + Crash in DOMParser due to out-of-memory conditions + * CVE-2023-4049 (bmo#1842658) + Fix potential race conditions when releasing platform objects + * CVE-2023-4050 (bmo#1843038) + Stack buffer overflow in StorageManager + * CVE-2023-4054 (bmo#1840777) + Lack of warning when opening appref-ms files + * CVE-2023-4055 (bmo#1782561) + Cookie jar overflow caused unexpected cookie jar state + * CVE-2023-4056 (bmo#1820587, bmo#1824634, bmo#1839235, + bmo#1842325, bmo#1843847) + Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1, + Firefox ESR 102.14, Thunderbird 115.1, and Thunderbird 102.14 + +------------------------------------------------------------------- @@ -6 +32 @@ - * CVE-2023-3417 (bmo#1835582) + * CVE-2023-3417 (bmo#1835582, boo#1213658) Old: ---- l10n-102.13.1.tar.xz thunderbird-102.13.1.source.tar.xz thunderbird-102.13.1.source.tar.xz.asc New: ---- l10n-102.14.0.tar.xz thunderbird-102.14.0.source.tar.xz thunderbird-102.14.0.source.tar.xz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ MozillaThunderbird.spec ++++++ --- /var/tmp/diff_new_pack.JxaRxV/_old 2023-08-03 17:30:08.387892914 +0200 +++ /var/tmp/diff_new_pack.JxaRxV/_new 2023-08-03 17:30:08.395892963 +0200 @@ -29,8 +29,8 @@ # major 69 # mainver %major.99 %define major 102 -%define mainver %major.13.1 -%define orig_version 102.13.1 +%define mainver %major.14.0 +%define orig_version 102.14.0 %define orig_suffix %{nil} %define update_channel release %define source_prefix thunderbird-%{orig_version} ++++++ l10n-102.13.1.tar.xz -> l10n-102.14.0.tar.xz ++++++ ++++++ tar_stamps ++++++ --- /var/tmp/diff_new_pack.JxaRxV/_old 2023-08-03 17:30:08.775895263 +0200 +++ /var/tmp/diff_new_pack.JxaRxV/_new 2023-08-03 17:30:08.787895335 +0200 @@ -1,11 +1,11 @@ PRODUCT="thunderbird" CHANNEL="esr102" -VERSION="102.13.1" +VERSION="102.14.0" VERSION_SUFFIX="" -PREV_VERSION="102.13.0" +PREV_VERSION="102.13.1" PREV_VERSION_SUFFIX="" #SKIP_LOCALES="" # Uncomment to skip l10n and compare-locales-generation RELEASE_REPO="https://hg.mozilla.org/releases/comm-esr102" -RELEASE_TAG="c1181d5307e80c773d3d2781b18f7bdd2353d66d" -RELEASE_TIMESTAMP="20230724161345" +RELEASE_TAG="d83d81499d87f2360995ae0448fcaa40e0cd106a" +RELEASE_TIMESTAMP="20230801134847" ++++++ thunderbird-102.13.1.source.tar.xz -> thunderbird-102.14.0.source.tar.xz ++++++ /work/SRC/openSUSE:Factory/MozillaThunderbird/thunderbird-102.13.1.source.tar.xz /work/SRC/openSUSE:Factory/.MozillaThunderbird.new.22712/thunderbird-102.14.0.source.tar.xz differ: char 15, line 1