-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 15 May 2025 17:54:43 +0200 Source: thunderbird Architecture: source Version: 1:128.10.1esr-1 Distribution: unstable Urgency: medium Maintainer: Carsten Schoenert <c.schoen...@t-online.de> Changed-By: Christoph Goehre <ch...@sigxcpu.org> Changes: thunderbird (1:128.10.1esr-1) unstable; urgency=medium . * [b31c095] New upstream version 128.10.1esr Fixed CVE issues in upstream version 128.10.1 (MFSA 2025-34): CVE-2025-3875: Sender Spoofing via Malformed From Header in Thunderbird CVE-2025-3877: Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links CVE-2025-3909: JavaScript Execution via Spoofed PDF Attachment and file:/// Link CVE-2025-3932: Tracking Links in Attachments Bypassed Remote Content Blocking Checksums-Sha1: 7aea9f7e3fb0fa3e3e5404d171ea87e6b604681b 8485 thunderbird_128.10.1esr-1.dsc c85029117dbc8e664e1a407dd4fcfcfef1c236a7 13221316 thunderbird_128.10.1esr.orig-thunderbird-l10n.tar.xz 6c5407a1bf6169e4fdd43fec4d5574ecbd06b79e 700033616 thunderbird_128.10.1esr.orig.tar.xz 2de68f7904502b5e57cd25ef0b985ed096ccf18d 548244 thunderbird_128.10.1esr-1.debian.tar.xz bfb88624942099eb2898c8d559045e0178cec3a1 6410 thunderbird_128.10.1esr-1_source.buildinfo Checksums-Sha256: bb2c64c5bfd147d919e99c96e5842aa615ba82a6ad27abb48f9679ce71517503 8485 thunderbird_128.10.1esr-1.dsc 6885f408eeb87ef7f1c57fee1a23737ed4f62ff3e183ddd8cf1c558af7c638e8 13221316 thunderbird_128.10.1esr.orig-thunderbird-l10n.tar.xz aa0cc78f9b7c84c1f2efbc1ee495d1d9495b602acbc8d191605339480991dafc 700033616 thunderbird_128.10.1esr.orig.tar.xz b233c54088bd4e5b6dc07a65880789a8080bd67a848bb801fee18dcf09d3c6b8 548244 thunderbird_128.10.1esr-1.debian.tar.xz f1e92469bd0c5899ae98536fe16a5b9925a268f6284b29353e371f3f9fc4ded9 6410 thunderbird_128.10.1esr-1_source.buildinfo Files: b3140967563721b8baf178d738f2bf23 8485 mail optional thunderbird_128.10.1esr-1.dsc 54312cca5550b95c6acb8d78ae4563dc 13221316 mail optional thunderbird_128.10.1esr.orig-thunderbird-l10n.tar.xz 16af9b51faac3e434c8c427f72ac87c8 700033616 mail optional thunderbird_128.10.1esr.orig.tar.xz 1a7867c061059cf48b8024fd48734fa8 548244 mail optional thunderbird_128.10.1esr-1.debian.tar.xz 179a5ceb2bcca9822f461052b5d4a6e8 6410 mail optional thunderbird_128.10.1esr-1_source.buildinfo
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEi5SBnCVVcKN0tizNJuPIdadEIO8FAmgmKTwACgkQJuPIdadE IO+GdRAAj/e9WNJ+++bQCEGqrIYSsEp0QSi4H59MeNIgxYlPc/vW3bys1+VW3FKs sy3wd5Hausoik+Cebv14oYJ1Ex6dJiFpDjsDslY4tFbMbBs5u0dDH6KeBpmKhE5b nK8SP3mO1mtzgdgkf3RGkEhyP/SyALTPeEWbRuc6L7liYRsiKEF0SKjpknuLPoxT CZVpdKyXMC8wvddQDdpOkrYFZ8G5MLqW9vPQ1ks/ZuFvEWJaPGsr6k6dyTLlyU/n ggjbenAQTneF2uqr5CXYAWH8n5ys7nvSxA6NqrSQTM4Lk5bgu7Tsj5HMQIMxxU99 D2hROWEmS/B7R7eHvmEhfiMliaFa1YAWuH7QwFqRRsedntpp8FInUHBm33/pWfOc pt1VOqHqPX6MjGcrAD7UCEQRik4XQEml4j295+B9/bF0doijSppQ1jjS8P9+xcvu wlLDt65GKwtadkUh/Jap7MHGNKHXbnbQCKcu48Ql8PNyfegejXFh4DMNH2YSyPUo a+Micz1yvMRbF45QG2Q1I87tQqhqHWQkGvyMhrJGgjIiE8mHMSktt2A4WbEedafr XiW/rFZ0Bj8GGxO8gXPxdWoyaf/fvsBspxLqMKqnZqyCPd1PfhC96epZsJRfx8U2 mH11OG+yMPDa94Rhqg5rd9UvYEkXLeeSasCZCO8p93V85i/5ev8= =XpL0 -----END PGP SIGNATURE-----
pgpn8zSY9R1fx.pgp
Description: PGP signature