thunderbird (1:68.9.0-1) unstable; urgency=medium
[ intrigeri ]
* [
fd13825] AppArmor: update profile from upstream at commit
860d2d9
(Closes: #960465)
[ Carsten Schoenert ]
* [
c310c40] New upstream version 68.9.0
Fixed CVE issues in upstream version 68.9.0 (MFSA 2020-22):
CVE-2020-12399: Timing attack on DSA signatures in NSS library
CVE-2020-12405: Use-after-free in SharedWorkerService
CVE-2020-12406: JavaScript Type confusion with NativeTypes
CVE-2020-12410: Memory safety bugs fixed in Thunderbird 68.9.0
CVE-2020-12398: Security downgrade with IMAP STARTTLS leads to
information leakage
[dgit import unpatched thunderbird 1:68.9.0-1]