thunderbird (1:60.8.0-1) unstable; urgency=medium
* [
49f4e91] New upstream version 60.8.0
Fixed CVE issues in upstream version 60.8.0 (MFSA 2019-23)
CVE-2019-9811: Sandbox escape via installation of malicious language pack
CVE-2019-11711: Script injection within domain through inner window reuse
CVE-2019-11712: Cross-origin POST requests can be made with NPAPI plugins
by following 308 redirects
CVE-2019-11713: Use-after-free with HTTP/2 cached stream
CVE-2019-11729: Empty or malformed p256-ECDH public keys may trigger a
segmentation fault
CVE-2019-11715: HTML parsing error can contribute to content XSS
CVE-2019-11717: Caret character improperly escaped in origins
CVE-2019-11719: Out-of-bounds read when importing curve25519 private key
CVE-2019-11730: Same-origin policy treats all files in a directory as
having the same-origin
CVE-2019-11709: Memory safety bugs fixed in Firefox 68, Firefox ESR 60.8,
and Thunderbird 60.8
[dgit import unpatched thunderbird 1:60.8.0-1]