thunderbird (1:102.2.1-1) unstable; urgency=medium
* [
e1d0f74] New upstream version 102.2.1
Fixed CVE issues in upstream version 102. (MFSA 2022-38):
CVE-2022-3033: Leaking of sensitive information when composing a response
to an HTML email with a META refresh tag
CVE-2022-3032: Remote content specified in an HTML document that was
nested inside an iframe's srcdoc attribute was not blocked
CVE-2022-3034: An iframe element in an HTML email could trigger a
network request
CVE-2022-36059: Matrix SDK bundled with Thunderbird vulnerable to
denial-of-service attack
[dgit import unpatched thunderbird 1:102.2.1-1]