Accepting request 1169354 from mozilla:Factory

- Mozilla Thunderbird 115.10.1
  https://www.thunderbird.net/en-US/thunderbird/115.10.1/releasenotes/
  * fixed hangup introduced with 115.10.0 (bmo#1891889)

- Mozilla Thunderbird 115.10.0
  https://www.thunderbird.net/en-US/thunderbird/115.10.0/releasenotes/
  MFSA 2024-20 (bsc#1222535)
  * CVE-2024-3852 (bmo#1883542)
    GetBoundName in the JIT returned the wrong object
  * CVE-2024-3854 (bmo#1884552)
    Out-of-bounds-read after mis-optimized switch statement
  * CVE-2024-3857 (bmo#1886683)
    Incorrect JITting of arguments led to use-after-free during
    garbage collection
  * CVE-2024-2609 (bmo#1866100)
    Permission prompt input delay could expire when not in focus
  * CVE-2024-3859 (bmo#1874489)
    Integer-overflow led to out-of-bounds-read in the OpenType sanitizer
  * CVE-2024-3861 (bmo#1883158)
    Potential use-after-free due to AlignedBuffer self-move
  * CVE-2024-3863 (bmo#1885855)
    Download Protections were bypassed by .xrm-ms files on Windows
  * CVE-2024-3302 (bmo#1881183)
    Denial of Service using HTTP/2 CONTINUATION frames
  * CVE-2024-3864 (bmo#1888333)
    Memory safety bug fixed in Firefox 125, Firefox ESR 115.10,
    and Thunderbird 115.10

OBS-URL: https://build.opensuse.org/request/show/1169354
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaThunderbird?expand=0&rev=333
This commit is contained in:
Ana Guerrero 2024-04-21 18:27:23 +00:00 committed by Git OBS Bridge
commit 94e186235a
9 changed files with 62 additions and 28 deletions

View File

@ -1,3 +1,37 @@
-------------------------------------------------------------------
Fri Apr 19 06:34:22 UTC 2024 - Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Thunderbird 115.10.1
https://www.thunderbird.net/en-US/thunderbird/115.10.1/releasenotes/
* fixed hangup introduced with 115.10.0 (bmo#1891889)
-------------------------------------------------------------------
Sun Apr 14 11:09:32 UTC 2024 - Wolfgang Rosenauer <wr@rosenauer.org>
- Mozilla Thunderbird 115.10.0
https://www.thunderbird.net/en-US/thunderbird/115.10.0/releasenotes/
MFSA 2024-20 (bsc#1222535)
* CVE-2024-3852 (bmo#1883542)
GetBoundName in the JIT returned the wrong object
* CVE-2024-3854 (bmo#1884552)
Out-of-bounds-read after mis-optimized switch statement
* CVE-2024-3857 (bmo#1886683)
Incorrect JITting of arguments led to use-after-free during
garbage collection
* CVE-2024-2609 (bmo#1866100)
Permission prompt input delay could expire when not in focus
* CVE-2024-3859 (bmo#1874489)
Integer-overflow led to out-of-bounds-read in the OpenType sanitizer
* CVE-2024-3861 (bmo#1883158)
Potential use-after-free due to AlignedBuffer self-move
* CVE-2024-3863 (bmo#1885855)
Download Protections were bypassed by .xrm-ms files on Windows
* CVE-2024-3302 (bmo#1881183)
Denial of Service using HTTP/2 CONTINUATION frames
* CVE-2024-3864 (bmo#1888333)
Memory safety bug fixed in Firefox 125, Firefox ESR 115.10,
and Thunderbird 115.10
-------------------------------------------------------------------
Wed Mar 20 13:55:26 UTC 2024 - Manfred Hollstein <manfred.h@gmx.net>

View File

@ -29,8 +29,8 @@
# major 69
# mainver %%major.99
%define major 115
%define mainver %major.9.0
%define orig_version 115.9.0
%define mainver %major.10.1
%define orig_version 115.10.1
%define orig_suffix %nil
%define update_channel release
%define source_prefix thunderbird-%{orig_version}

3
l10n-115.10.1.tar.xz Normal file
View File

@ -0,0 +1,3 @@
version https://git-lfs.github.com/spec/v1
oid sha256:27fe8ba17c28058811987470b8cb3522878d36c671cf668e4a1a383048a7997d
size 28322844

View File

@ -1,3 +0,0 @@
version https://git-lfs.github.com/spec/v1
oid sha256:7943b97cba342c3a998d7ee4f2dd2cf3eac73201ab9b1f332556aaa637abd3b9
size 29763000

View File

@ -1,10 +1,10 @@
PRODUCT="thunderbird"
CHANNEL="esr115"
VERSION="115.9.0"
VERSION="115.10.1"
VERSION_SUFFIX=""
PREV_VERSION="115.8.1"
PREV_VERSION="115.10.0"
PREV_VERSION_SUFFIX=""
#SKIP_LOCALES="" # Uncomment to skip l10n and compare-locales-generation
RELEASE_REPO="https://hg.mozilla.org/releases/comm-esr115"
RELEASE_TAG="1e95a096fd3c6053c4eeeca935eb8227cf9ee25c"
RELEASE_TIMESTAMP="20240314154241"
RELEASE_TAG="24e9961527d4cbb7f3f92687c40ee2fa96fb44cb"
RELEASE_TIMESTAMP="20240417192958"

View File

@ -0,0 +1,3 @@
version https://git-lfs.github.com/spec/v1
oid sha256:1b81af21880f381f9a00c18480f40bfc9fbd1b1f62cdea4048b6d6d84f9850da
size 532507896

View File

@ -0,0 +1,16 @@
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEErdcHlHlwDcrf3VM34207E/PZMnQFAmYglq8ACgkQ4207E/PZ
MnS2uw/+LCitQpgV8z9PKgg4nqFg3X3aPrG5BbRfyxIayhZ7JOq+rINDU0VPo2wo
YNPuqXt3LaQUGYpKlVyQITelgwvd5dNOvaYMKDS4tqXIUZgs2wu5/5M1knlI/s6v
MGX9vOVbTna7/29RKAIffcKYvgYn6YpzYUvPJMJou6j1iFBjBG9hd8WRFUXFOR29
LpPtnu4h5hxrkFHzr+wMBlloYbtbtJmLJw1uxpTkwv7uAF15PyeHdyDg7QpEnaQ+
9T5bo/9ZLodINZcLynLGiw+zeelGOwjEsyc/GRXPLuMpyePemGf/Ouc4tC/8b1XS
RmTTO2HCEVcp9Q2eooU4KerJFrVAF3a2+4jHcQl7Hls82+iJqrMrEaJ4+cOMWKaS
Hfwx6P64E0Uzo2uuHdnywVdLR7DHQoAgHsOnhs3sg9DJC+oUNyQuj5nO+difxYVA
OzX+WUONAPsQG7j8O9lLrQZmh48pRbQ1QhE2HRPfLx49Gxb5bxDq7D56XCvxJm6T
gEBwAp2pFAS6WTKQxcDx0Hw8ich7Nkfv2pvRdCwArf+s7QZj/YcKOZ7l8oRKnpIc
pY3oAA/kpwRoBuegK82jtQupqOKo2ELoR6PUZoRXKIIuzIwfxMJlEVOw6PPs8zAW
WX8KhVHtQh8lgIKYxzDgA672IA5jHCqgtD5Nu8j8rYzn1E8TpGQ=
=2+Hu
-----END PGP SIGNATURE-----

View File

@ -1,3 +0,0 @@
version https://git-lfs.github.com/spec/v1
oid sha256:2aeb77ca7038df6f3d306f9c3d2a4ea615af0edcf0f7290215ca5f30c1290e57
size 535516012

View File

@ -1,16 +0,0 @@
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEErdcHlHlwDcrf3VM34207E/PZMnQFAmX0cvkACgkQ4207E/PZ
MnQsig/9ENVeCyVRzE8NJpHqJwBnxztGaqkeOyDxonbKEQ1NTwrvn5hIRdHkWiRz
cYo0SH5Cw7cjOrhAS+fWQdx43RaTRwVNN8nJv6HfxJFL5OSQ/QbHkunVNg0Yq9TE
RYv+D/9IX+Fm48ZNQ5wl5dkCbhg0euFoPSxqZKrvi7U0LJ1uHtle9TOXztn+I0s1
uafbMiuLdNi8r4UIcopYpoMTg0Yt9hbKIdG9tFF/thotT5DJeN3Vrx/rBh2cMZX+
wvwbXdQziVsLGqpQ14dl9vCsZqujoiRG+G4oAo9nngyQZgF+aucEev1vAq7YFbaM
Q3Tc+V8JVpJxk1TYS08CU8Ph1ZuCJOiixCwjTzXo5RqOUrC5zAd29fcQkMqqyGB+
p6nLvXFwlWdroLsROCcMH9MmJzAFDhfUms41AeUvyp+1sUyqpkzJBczBjHOi0DQ6
tmFjgK+Ph8VAct4kIBKI7FRkn5w3e7/Xr670oc/zFo0AunWBktowx5R2LyXqXpmk
hIlYC3n5QhtX08SxqgFsV18rFUrDXBuMssmJbcet7ZETCdFHjKk9CITD5zsi3oQW
mLR+IkZYrzEv4btvJdd8W8o4wUv2VPHCDP7Pxkk1V2/1h8n4+BhaO3E4GNz17odZ
l1h1EkhMUErlApPKhVd2EflF38v7uKhSw2WKTiQpwzZSNk2B00k=
=WHyd
-----END PGP SIGNATURE-----