-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 07 Aug 2024 18:44:31 +0200 Source: thunderbird Binary: thunderbird thunderbird-dbgsym Architecture: amd64 Version: 1:115.14.0-1~deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-csail-01) Changed-By: Carsten Schoenert Description: thunderbird - mail/news client with RSS, chat and integrated spam filter suppor Changes: thunderbird (1:115.14.0-1~deb12u1) bookworm-security; urgency=medium . * [d608c75] New upstream version 115.14.0 Fixed CVE issues in upstream version 115.1 (MFSA 2024-38): CVE-2024-7519: Out of bounds memory access in graphics shared memory handling CVE-2024-7521: Incomplete WebAssembly exception handing CVE-2024-7522: Out of bounds read in editor component CVE-2024-7525: Missing permission check when creating a StreamFilter CVE-2024-7526: Uninitialized memory used by WebGL CVE-2024-7527: Use-after-free in JavaScript garbage collection CVE-2024-7529: Document content could partially obscure security prompts Checksums-Sha1: 56b23d723fc7c3780043e0ca7de5591f2267ce6b 431322496 thunderbird-dbgsym_115.14.0-1~deb12u1_amd64.deb ee35f5fefc69e63dcaffe1ac302b460f668036d2 20369 thunderbird_115.14.0-1~deb12u1_amd64-buildd.buildinfo a3146becf985cd12c573c420bfbb50c61f4e43fe 58311732 thunderbird_115.14.0-1~deb12u1_amd64.deb Checksums-Sha256: 3f72a1e8ffd3f04e82c4fd827e0aab9a749b762b3aea93a7c7e628d53797727f 431322496 thunderbird-dbgsym_115.14.0-1~deb12u1_amd64.deb 354789ec55dcabc2cc02ecfa672283ba4ad5f63ec91629417093314bb0bc9248 20369 thunderbird_115.14.0-1~deb12u1_amd64-buildd.buildinfo 6b9e1218413ff1676a8fdd8608fd2988c3a60b940f13c054fe4415dabc7041b8 58311732 thunderbird_115.14.0-1~deb12u1_amd64.deb Files: d6e2fc22fc9882e81ace5523d12f219e 431322496 debug optional thunderbird-dbgsym_115.14.0-1~deb12u1_amd64.deb 1272dac52fb0c20878e23fa57796b6cd 20369 mail optional thunderbird_115.14.0-1~deb12u1_amd64-buildd.buildinfo 650e2c54bf4c6bab2c6b28eb8bf52c9f 58311732 mail optional thunderbird_115.14.0-1~deb12u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEvy6d65NNYPbL6IQIEQ1nooK/IAQFAma0wGUACgkQEQ1nooK/ IARH+Q/+MSj3Nl4iXA47T47nQoDrSBg+bDhNufW2G/EEm1B2PCwQaCbBS7ZokkUH SUFfeRlyw+0sDKWyyye6M7fvTtC1c2Ps3gl4q1LGjCHy5Tf4y7bva1bQVmCEcp/B W2f+oGHWLQgo1qESWsAylIDnAx6dPrrkqMF1SHt6BqmzziilsblXknRcWnIgnIgu u9MbyZms4v6Wgyd9re1gZLpHKl7fYAjU8C9uI1Gipec++cJxOstJozysguRDrKWR HwwAjBziWkVxFNh9E6am2Xn72XfXPKtr/RpOPbTqi6ryt3Lv1r6Bz+LfJY5m5BUu CBuDzTCyT5kXlaas1InzYHR8Ic5O+ST//i3aXbBhBec+8iHbovSL7JuPyYT05wxV JSDHmYfs48OYdNW7xyzGSJwBKgTIzcEcsZcJu75rpSnND+OCyX7Su7liZJDbpII6 DGDBelRmHNv3BXMj7vqWb+zwcbzYB2RqNBtiiHMQyzuMw2XtpuSH1a4DvVRH6X4h IdpY6V9gly8ZjZnllsRk7XrcQ0k7S+bmeceDn7MdphFfnsF9zXQGT0wWF6qWxlyg pIWEuSgUQ8J63oJis5NIkej2qnFqDG5xBTYowC9i77pefhL+Q8zfSFuxA2HBw7RR bmwN2sBu6MQiMWbIbdsYidHX8P3/QmTCllepI8gAeQK6ClOm4f8= =wrH9 -----END PGP SIGNATURE-----