-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 07 Aug 2024 18:44:31 +0200 Source: thunderbird Binary: thunderbird thunderbird-dbgsym Architecture: i386 Version: 1:115.14.0-1~deb12u1 Distribution: bookworm-security Urgency: medium Maintainer: i386 Build Daemon (x86-grnet-01) Changed-By: Carsten Schoenert Description: thunderbird - mail/news client with RSS, chat and integrated spam filter suppor Changes: thunderbird (1:115.14.0-1~deb12u1) bookworm-security; urgency=medium . * [d608c75] New upstream version 115.14.0 Fixed CVE issues in upstream version 115.1 (MFSA 2024-38): CVE-2024-7519: Out of bounds memory access in graphics shared memory handling CVE-2024-7521: Incomplete WebAssembly exception handing CVE-2024-7522: Out of bounds read in editor component CVE-2024-7525: Missing permission check when creating a StreamFilter CVE-2024-7526: Uninitialized memory used by WebGL CVE-2024-7527: Use-after-free in JavaScript garbage collection CVE-2024-7529: Document content could partially obscure security prompts Checksums-Sha1: f4e822027d72b25014a5bdf619a54d603a990fb6 7534588 thunderbird-dbgsym_115.14.0-1~deb12u1_i386.deb d9a1ab28c921bddf585736d9586ad6e8df3db0a4 20366 thunderbird_115.14.0-1~deb12u1_i386-buildd.buildinfo 6ccfc37651db0c9550aa6d19a087a192528cc4fa 60504636 thunderbird_115.14.0-1~deb12u1_i386.deb Checksums-Sha256: 2a863a173300a28468c5627d44476d0fcf6c861e0d3a6aa0dae2da5f5c2efbee 7534588 thunderbird-dbgsym_115.14.0-1~deb12u1_i386.deb 7e1d2ac95aca61fb21e52cf9529ad9d04430210fb82668217c499430371e2d6b 20366 thunderbird_115.14.0-1~deb12u1_i386-buildd.buildinfo bf93f843caf96169d2a8bc22b1e13fc6db8cd31f2bea2a658053b3c8fc1d8f8f 60504636 thunderbird_115.14.0-1~deb12u1_i386.deb Files: f8f721f19f28a3a4b9e888a5174f105b 7534588 debug optional thunderbird-dbgsym_115.14.0-1~deb12u1_i386.deb d84f77eea6eb0de8bd452e1efdbf428b 20366 mail optional thunderbird_115.14.0-1~deb12u1_i386-buildd.buildinfo bb427bf7c1b75c9125ba45cf86264aa6 60504636 mail optional thunderbird_115.14.0-1~deb12u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEyTfXx8sBpQ0Lh3cUU9a0/LcaTpMFAma0v1QACgkQU9a0/Lca TpMGaQ/+MiNbGB0ZQq3Jbqtue82T+TfQrlWAG9dbFyoNM4sHsSrTWIJlons2c/yz +mEtlSAIGbPTebg0bR/ZaX2Hpmd07VjVcXtc43FF6RHSzVI8rDsu0ur2ZkLQiM+f HcayfirkGr8wFcz6mxsv4cdlqHda012wDUU+uGr8y6cAb01eEIH2kPSZW2yCVSnn 0FM62DsqJovGlXugZxrZ/KDwqWw9cX+PoZq9E8RdlmfRG26D+GBvSmdpvOh4jmqQ siNkj50xFTUZtojId1zExV4SyUjdRi3kxrl/tu06m93dZ6WIzmEwKI99MJC77mN0 Ukx2jgXuAc2TD9DzJOb27wFZBaM3XFDT0/phGTGKNpOKD6vjYyA+06cw/zblMHg+ BDUDVx/3YX/gu2noSCTKW1GwBHd47nBoX1KdwwVx5PAk3+ak1hQuvvtNNSmEjd5H xkBiLoLHaDg4zUhNr0T0Wjbpf5JRRzR81l+65j7q1qnl6rye/U7YomDpzN/Qi2ML eBR95vkpVjqquu/dnibiuNYxhkMmyLEPuPRq8CJn+orogixpMiRIsLF1U7LZmv+j 6AfX644flrX6Bax+4cc8t4LF6uYEMLBGW70lv+DuTgKfxdm26beR2jMToIb4I/u2 L68I+QV3J59hPESkixyuCAt+56d5rMAvxAssmetkUtuWB4Jc6FU= =D8a6 -----END PGP SIGNATURE-----