thunderbird (1:91.9.0-1) unstable; urgency=medium
* [
88b99d1] New upstream version 91.9.0
Fixed CVE issues in upstream version 91.9 (MFSA 2022-18):
CVE-2022-1520: Incorrect security status shown after viewing an attached
email
CVE-2022-29914: Fullscreen notification bypass using popups
CVE-2022-29909: Bypassing permission prompt in nested browsing contexts
CVE-2022-29916: Leaking browser history with CSS variables
CVE-2022-29911: iframe sandbox bypass
CVE-2022-29912: Reader mode bypassed SameSite cookies
CVE-2022-29913: Speech Synthesis feature not properly disabled
CVE-2022-29917: Memory safety bugs fixed in Thunderbird 91.9
[dgit import unpatched thunderbird 1:91.9.0-1]