thunderbird (1:115.8.0-1) unstable; urgency=medium
* [
68f2fbe] New upstream version 115.8.0
Fixed CVE issues in upstream version 115.8 (MFSA 2024-07):
CVE-2024-1546: Out-of-bounds memory read in networking channels
CVE-2024-1547: Alert dialog could have been spoofed on another site
CVE-2024-1548: Fullscreen Notification could have been hidden by select
element
CVE-2024-1549: Custom cursor could obscure the permission dialog
CVE-2024-1550: Mouse cursor re-positioned unexpectedly could have led to
unintended permission grants
CVE-2024-1551: Multipart HTTP Responses would accept the Set-Cookie
header in response parts
CVE-2024-1552: Incorrect code generation on 32-bit ARM devices
CVE-2024-1553: Memory safety bugs fixed in Firefox 123, Firefox ESR 115.8,
and Thunderbird 115.8
[dgit import unpatched thunderbird 1:115.8.0-1]