thunderbird (1:78.10.0-1) unstable; urgency=medium
* [
f38d78f] New upstream version 78.10.0
Fixed CVE issues in upstream version 78.10 (MFSA 2021-15):
CVE-2021-23994: Out of bound write due to lazy initialization
CVE-2021-23995: Use-after-free in Responsive Design Mode
CVE-2021-23998: Secure Lock icon could have been spoofed
CVE-2021-23961: More internal network hosts could have been probed by a
malicious webpage
CVE-2021-23999: Blob URLs may have been granted additional privileges
CVE-2021-24002: Arbitrary FTP command execution on FTP servers using an
encoded URL
CVE-2021-29945: Incorrect size computation in WebAssembly JIT could lead
to null-reads (This issue only affected x86-32 platforms.)
CVE-2021-29946: Port blocking could be bypassed
CVE-2021-29948: Race condition when reading from disk while verifying
signatures
[dgit import unpatched thunderbird 1:78.10.0-1]