-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 16 Sep 2026 16:41:34 +0200
Source: thunderbird
Architecture: source
Version: 1:153.3.0esr-1
Distribution: unstable
Urgency: medium
Maintainer: Carsten Schoenert <[email protected]>
Changed-By: Carsten Schoenert <[email protected]>
Changes:
 thunderbird (1:153.3.0esr-1) unstable; urgency=medium
 .
   [ Christoph Goehre ]
   * [4340b21] d/control: re-Adding s390x architecture
 .
   [ Carsten Schoenert ]
   * [c7926a8] New upstream version 153.3.0esr
     Fixed CVE issues in upstream version 153.3 (MFSA 2026-93):
     CVE-2026-92005: Use-after-free in the Audio/Video: Web Codecs component
     CVE-2026-92006: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92007: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92008: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92009: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92010: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92011: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92012: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92013: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: CanvasWebGL component
     CVE-2026-92015: Privilege escalation in the WebExtensions component
     CVE-2026-92035: Sandbox escape due to incorrect boundary conditions in
                     the Graphics component
     CVE-2026-92016: Use-after-free in the Disability Access APIs component
     CVE-2026-92017: Privilege escalation in the DOM: Service Workers
                     component
     CVE-2026-92018: Sandbox escape in the DOM: Core &amp; HTML component
     CVE-2026-92019: Mitigation bypass in the Remote Settings Client component
     CVE-2026-92020: Privilege escalation due to incorrect boundary conditions
                     in the Graphics: WebRender component
     CVE-2026-92022: Use-after-free in the DOM: HTML Parser component
     CVE-2026-92023: Use-after-free in the XML component
     CVE-2026-92024: Use-after-free in the SVG component
     CVE-2026-92025: Use-after-free in the DOM: Navigation component
     CVE-2026-92026: Use-after-free in the Networking component
     CVE-2026-92027: Use-after-free in the DOM: Streams component
     CVE-2026-92028: Use-after-free in the DOM: Core &amp; HTML component
     CVE-2026-92029: Use-after-free in the SVG component
     CVE-2026-92038: Mitigation bypass in the Remote Settings Client component
     CVE-2026-92039: Mitigation bypass in the DOM: Notifications component
     CVE-2026-92041: Mitigation bypass in the DOM: Networking component
     CVE-2026-92042: Race condition in the DOM: Content Processes component
     CVE-2026-92043: Privilege escalation due to incorrect boundary conditions
                     in the Audio/Video component
     CVE-2026-92044: Information disclosure in the Networking: HTTP component
     CVE-2026-92045: Sandbox escape due to incorrect boundary conditions in
                     the WebRTC component
     CVE-2026-92030: Mitigation bypass in the DOM: Copy &amp; Paste and Drag
                     & Drop component
     CVE-2026-92046: Use-after-free in the Graphics component
     CVE-2026-92047: Privilege escalation in the Crash Reporting component
     CVE-2026-92048: Sandbox escape due to incorrect boundary conditions in
                     the Widget: Win32 component
     CVE-2026-92049: Use-after-free in the Widget: Win32 component
     CVE-2026-92052: Privilege escalation due to uninitialized memory in the
                     Graphics: CanvasWebGL component
     CVE-2026-92053: Privilege escalation in the Graphics: CanvasWebGL
                     component
     CVE-2026-92054: Privilege escalation in the Memory component
     CVE-2026-92055: Privilege escalation in the DevTools component
     CVE-2026-92056: Use-after-free in the Graphics: Text component
     CVE-2026-92057: Mitigation bypass in the Enterprise Policies component
     CVE-2026-92031: Information disclosure in the Graphics: ImageLib
                     component
     CVE-2026-92032: Sandbox escape due to invalid pointer in the Graphics
                     component
     CVE-2026-92058: Use-after-free in the Graphics component
     CVE-2026-92059: Incorrect boundary conditions in the DOM: Editor
                     component
     CVE-2026-92060: Use-after-free in the Internationalization component
     CVE-2026-92062: Privilege escalation in the Session Restore component
     CVE-2026-92064: Sandbox escape due to incorrect boundary conditions in
                     the Widget: Win32 component
     CVE-2026-92065: Sandbox escape due to incorrect boundary conditions in
                     the Widget: Win32 component
     CVE-2026-92067: Use-after-free in the Widget: Gtk component
     CVE-2026-92068: Site isolation issue in the Reader Mode component
     CVE-2026-92069: Spoofing issue in the DOM: Navigation component
     CVE-2026-92070: Information disclosure in the Networking component
     CVE-2026-92071: Sandbox escape due to incorrect boundary conditions in
                     the Widget: Win32 component
     CVE-2026-92072: Incorrect boundary conditions in the Safe Browsing
                     component
     CVE-2026-92073: Privilege escalation in the Enterprise Policies
                     component
     CVE-2026-92074: Mitigation bypass in the Popup Blocker component
     CVE-2026-92075: Mitigation bypass in the Networking component
     CVE-2026-92076: Incorrect boundary conditions in the Networking
                      component
     CVE-2026-92077: Denial-of-service in the SVG component
     CVE-2026-92078: Denial-of-service in the Security component
     CVE-2026-92079: Mitigation bypass in the Widget: Win32 component
   * [724bd8a] d/thunderbird.lintian-overrides: Drop override about bzip2
   * [2d39531] d/copyright: Fix misspelled word thunderbird-l10n
Checksums-Sha1:
 bb163cd671cce660275b003e527c6e0a87b2cce8 8467 thunderbird_153.3.0esr-1.dsc
 895ce456782e29d9ef3edf2123ef8bcf8035b199 12832576 
thunderbird_153.3.0esr.orig-thunderbird-l10n.tar.xz
 800a296e75e0568af7190810e0437c6ae837f37b 903565728 
thunderbird_153.3.0esr.orig.tar.xz
 8d263b20caabd33d5721b06028b75d83f5d1ebb2 556556 
thunderbird_153.3.0esr-1.debian.tar.xz
 672dde3f35a3f19ed15f7ae34b2eac970210a75f 41011 
thunderbird_153.3.0esr-1_amd64.buildinfo
Checksums-Sha256:
 0f4023b891544380afaf0c0196c0c7e189664e4cf1f0d9c90a9c8f53284480bf 8467 
thunderbird_153.3.0esr-1.dsc
 eca895eb471d200cb52c4a4fb0302ad9604e9d93f354599589958dcd9e91a4eb 12832576 
thunderbird_153.3.0esr.orig-thunderbird-l10n.tar.xz
 e0cdd0a3feec2dfc530f50fdc48db522f1299bdf1a37c1a29631b581c2c5cc11 903565728 
thunderbird_153.3.0esr.orig.tar.xz
 35f1d9e99301cd8d6792e9bc283f83310609349809e8e0132d3752d38f5f55e1 556556 
thunderbird_153.3.0esr-1.debian.tar.xz
 73f3886d80058fc4b3d47f77e827102879f05154df544370251ffbc3fd8f7b89 41011 
thunderbird_153.3.0esr-1_amd64.buildinfo
Files:
 058f80696ddded73eff0b6442fb65100 8467 mail optional 
thunderbird_153.3.0esr-1.dsc
 0166f2f697b2d642cb05603fa49cf655 12832576 mail optional 
thunderbird_153.3.0esr.orig-thunderbird-l10n.tar.xz
 549c099e9f834a7c44d806a1a2a0da34 903565728 mail optional 
thunderbird_153.3.0esr.orig.tar.xz
 ee55ab062e190c7b0ed29ea98b775c9c 556556 mail optional 
thunderbird_153.3.0esr-1.debian.tar.xz
 491470efe6701da8e9961b6183dc45ee 41011 mail optional 
thunderbird_153.3.0esr-1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJMBAEBCgA2FiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmqrlRkYHGMuc2Nob2Vu
ZXJ0QHQtb25saW5lLmRlAAoJEIMBYBQlHR2w9jwP/0LKCkOKwLYO8x5Bxx240fSv
N7JdhaHq9Up1K5Wta1vCwSS60zeAg4PeCs1IPkYjuv7DBemr2LtSDGL13+U/MbRX
bZWM7EHkGJM7dj/YA+xJo+P0LJvi76BMWS+Gv0s0H2oO4FMEsmPRST8xLu8EAvEx
9st6IPdLdfbo5JoNJoLUR4XC/TMKEkTBFAa5hXo0Hje+TVFKyFZyBKhdGbfBzxVh
/cHDbyODUcIailXG7jMr0StIRojfj5fjW14BHPGZhVVHYxOB6bKnPh+iwa7Pfu3o
5s46Qh+57XQ5KriX41x+cHncm73IUf4Orju1UmyGXuEsWwLyMWIJ1wrxGfHVHa4N
Xoq532MmuGsSd166VCaMBLh45YBWEer3VNByYc09YAB+DPJglxNY6CFh1mX7jhzN
L3QGc5gJIDa6YroBP1ArZbgKudsb2618Pe/pAu/xJgbyjnNsB61wbYtEV8NU/WJR
qziO5zRNhOYK1Kb7y+Au66PSmQ9lW6O4Ma/ZhpFq/j++60VRM2+eSVLWmoG80GI7
fPJ6zpkiaAQzynrgBnFhL8wS+IMJzct0St0HuCw+OpB33gKMBm8a2QsFaALi3mNB
wP8n2EwafAqQxC3Vw5yXnrckG8r6y9N46iaoAw2pYjGbx9bTSBqm0UH8hjCHVEEB
NNLYYCLKoOu9yprBb0Zt
=i1PY
-----END PGP SIGNATURE-----

Attachment: pgpfgK43Dbb6a.pgp
Description: PGP signature

Reply via email to