- thunderbird (1:60.7.2-1+rpi1) buster-staging; urgency=medium
++thunderbird (1:60.8.0-1+rpi1) bullseye-staging; urgency=medium
+
+ [changes brought over from firefox-esr 60.3.0esr-1+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Wed, 05 Dec 2018 06:56:52 +0000]
+ * Hack broken rust target selection so it produces the right target
+ on raspbian.
+ * Fix clean target.
+
+ [changes introduced in 60.4.0-1+rpi1 by Peter Michael Green]
+ * Further fixes to clean target (still not completely fixed :( ).
+ * Add build-depends on clang-6.0 (to match libclang-6.0-dev)
+
- -- Raspbian forward porter <root@raspbian.org> Thu, 27 Jun 2019 18:08:02 +0000
++ -- Raspbian forward porter <root@raspbian.org> Thu, 18 Jul 2019 04:30:56 +0000
++
+ thunderbird (1:60.8.0-1) unstable; urgency=medium
+
+ * [49f4e91] New upstream version 60.8.0
+ Fixed CVE issues in upstream version 60.8.0 (MFSA 2019-23)
+ CVE-2019-9811: Sandbox escape via installation of malicious language pack
+ CVE-2019-11711: Script injection within domain through inner window reuse
+ CVE-2019-11712: Cross-origin POST requests can be made with NPAPI plugins
+ by following 308 redirects
+ CVE-2019-11713: Use-after-free with HTTP/2 cached stream
+ CVE-2019-11729: Empty or malformed p256-ECDH public keys may trigger a
+ segmentation fault
+ CVE-2019-11715: HTML parsing error can contribute to content XSS
+ CVE-2019-11717: Caret character improperly escaped in origins
+ CVE-2019-11719: Out-of-bounds read when importing curve25519 private key
+ CVE-2019-11730: Same-origin policy treats all files in a directory as
+ having the same-origin
+ CVE-2019-11709: Memory safety bugs fixed in Firefox 68, Firefox ESR 60.8,
+ and Thunderbird 60.8
+
+ -- Carsten Schoenert <c.schoenert@t-online.de> Tue, 09 Jul 2019 22:09:04 +0200
thunderbird (1:60.7.2-1) unstable; urgency=medium