From: Raspbian automatic forward porter Date: Thu, 18 Jul 2019 04:30:59 +0000 (+0100) Subject: Merge version 1:60.7.2-1+rpi1 and 1:60.8.0-1 to produce 1:60.8.0-1+rpi1 X-Git-Tag: archive/raspbian/1%60.8.0-1+rpi1^0 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=8c1f5655a680c50d6313dcc47afabb03c14751ca;p=thunderbird.git Merge version 1:60.7.2-1+rpi1 and 1:60.8.0-1 to produce 1:60.8.0-1+rpi1 --- 8c1f5655a680c50d6313dcc47afabb03c14751ca diff --cc debian/changelog index d920e5240b,63f6daab9b..e7c7e13494 --- a/debian/changelog +++ b/debian/changelog @@@ -1,15 -1,23 +1,36 @@@ - thunderbird (1:60.7.2-1+rpi1) buster-staging; urgency=medium ++thunderbird (1:60.8.0-1+rpi1) bullseye-staging; urgency=medium + + [changes brought over from firefox-esr 60.3.0esr-1+rpi1 by Peter Michael Green at Wed, 05 Dec 2018 06:56:52 +0000] + * Hack broken rust target selection so it produces the right target + on raspbian. + * Fix clean target. + + [changes introduced in 60.4.0-1+rpi1 by Peter Michael Green] + * Further fixes to clean target (still not completely fixed :( ). + * Add build-depends on clang-6.0 (to match libclang-6.0-dev) + - -- Raspbian forward porter Thu, 27 Jun 2019 18:08:02 +0000 ++ -- Raspbian forward porter Thu, 18 Jul 2019 04:30:56 +0000 ++ + thunderbird (1:60.8.0-1) unstable; urgency=medium + + * [49f4e91] New upstream version 60.8.0 + Fixed CVE issues in upstream version 60.8.0 (MFSA 2019-23) + CVE-2019-9811: Sandbox escape via installation of malicious language pack + CVE-2019-11711: Script injection within domain through inner window reuse + CVE-2019-11712: Cross-origin POST requests can be made with NPAPI plugins + by following 308 redirects + CVE-2019-11713: Use-after-free with HTTP/2 cached stream + CVE-2019-11729: Empty or malformed p256-ECDH public keys may trigger a + segmentation fault + CVE-2019-11715: HTML parsing error can contribute to content XSS + CVE-2019-11717: Caret character improperly escaped in origins + CVE-2019-11719: Out-of-bounds read when importing curve25519 private key + CVE-2019-11730: Same-origin policy treats all files in a directory as + having the same-origin + CVE-2019-11709: Memory safety bugs fixed in Firefox 68, Firefox ESR 60.8, + and Thunderbird 60.8 + + -- Carsten Schoenert Tue, 09 Jul 2019 22:09:04 +0200 thunderbird (1:60.7.2-1) unstable; urgency=medium