Commit Graph

453 Commits

Author SHA256 Message Date
Wolfgang Rosenauer
bd13e76487 - Mozilla Thunderbird 115.5.2
Bugfix release
  https://www.thunderbird.net/en-US/thunderbird/115.5.2/releasenotes/

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=739
2023-12-12 22:10:43 +00:00
Wolfgang Rosenauer
5835378f85 - Mozilla Thunderbird 115.5.1
Bugfix release
  https://www.thunderbird.net/en-US/thunderbird/115.5.1/releasenotes
  * Advanced GnuPG keys may be protected with an unexpected passphrase
  * OpenPGP signatures rejected due to mismatched signature timestamp
    now display signature timestamp and clarifying message
  * Advanced address book search did not return results if display name
    was left blank
  * Clicking on attendee when inviting attendees added the attendee twice

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=737
2023-11-29 07:32:44 +00:00
Wolfgang Rosenauer
480e0302f0 MFSA 2023-52 (bsc#1217230)
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=735
2023-11-23 08:16:17 +00:00
Wolfgang Rosenauer
55bb2ec82a - Mozilla Thunderbird 115.5.0
https://www.thunderbird.net/en-US/thunderbird/115.5.0/releasenotes
  MFSA 2023-52 (bsc#)
  * CVE-2023-6204 (bmo#1841050)
    Out-of-bound memory access in WebGL2 blitFramebuffer
  * CVE-2023-6205 (bmo#1854076)
    Use-after-free in MessagePort::Entangled
  * CVE-2023-6206 (bmo#1857430)
    Clickjacking permission prompts using the fullscreen transition
  * CVE-2023-6207 (bmo#1861344)
    Use-after-free in ReadableByteStreamQueueEntry::Buffer
  * CVE-2023-6208 (bmo#1855345)
    Using Selection API would copy contents into X11 primary
    selection.
  * CVE-2023-6209 (bmo#1858570)
    Incorrect parsing of relative URLs starting with "///"
  * CVE-2023-6212 (bmo#1658432, bmo#1820983, bmo#1829252, bmo#1856072,
    bmo#1856091, bmo#1859030, bmo#1860943, bmo#1862782)
    Memory safety bugs fixed in Firefox 120, Firefox ESR 115.5,
    and Thunderbird 115.5

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=734
2023-11-23 08:14:02 +00:00
Wolfgang Rosenauer
328f51e3db - Mozilla Thunderbird 115.4.3
Bugfix release
  https://www.thunderbird.net/en-US/thunderbird/115.4.3/releasenotes

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=732
2023-11-16 09:04:06 +00:00
Wolfgang Rosenauer
1bac4101c8 - Mozilla Thunderbird 115.4.2
https://www.thunderbird.net/en-US/thunderbird/115.4.2/releasenotes
- build using rust/cargo 1.72 (1.69 about to be dropped from Factory)

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=730
2023-11-08 12:10:27 +00:00
Wolfgang Rosenauer
62f65fe0ea - Mozilla Thunderbird 115.4.1
https://www.thunderbird.net/en-US/thunderbird/115.4.1/releasenotes
  https://www.thunderbird.net/en-US/thunderbird/115.4.0/releasenotes
  MFSA 2023-47 (bsc#1216338)
  * CVE-2023-5721 (bmo#1830820)
    Queued up rendering could have allowed websites to clickjack
  * CVE-2023-5732 (bmo#1690979, bmo#1836962)
    Address bar spoofing via bidirectional characters
  * CVE-2023-5724 (bmo#1836705)
    Large WebGL draw could have led to a crash
  * CVE-2023-5725 (bmo#1845739)
    WebExtensions could open arbitrary URLs
  * CVE-2023-5726 (bmo#1846205)
    Full screen notification obscured by file open dialog on macOS
  * CVE-2023-5727 (bmo#1847180)
    Download Protections were bypassed by .msix, .msixbundle,
    .appx, and .appxbundle files on Windows
  * CVE-2023-5728 (bmo#1852729)
    Improper object tracking during GC in the JavaScript engine
    could have led to a crash.
  * CVE-2023-5730 (bmo#1836607, bmo#1840918, bmo#1848694, bmo#1848833,
    bmo#1850191, bmo#1850259, bmo#1852596, bmo#1853201, bmo#1854002,
    bmo#1855306, bmo#1855640, bmo#1856695)
    Memory safety bugs fixed in Firefox 119, Firefox ESR 115.4,
    and Thunderbird 115.4.1
- removed obsolete mozilla-bmo1846703.patch

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=728
2023-10-25 06:36:45 +00:00
Wolfgang Rosenauer
f4ecfaed93 Accepting request 1120115 from home:AndreasStieger:branches:mozilla:Factory
Mozilla Thunderbird 115.3.3

OBS-URL: https://build.opensuse.org/request/show/1120115
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=727
2023-10-24 21:00:55 +00:00
Wolfgang Rosenauer
6c4666a6b7 - Mozilla Thunderbird 115.3.2
Bugfix release
  https://www.thunderbird.net/en-US/thunderbird/115.3.2/releasenotes

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=725
2023-10-11 06:35:40 +00:00
Wolfgang Rosenauer
c1979ea7d9 - Mozilla Thunderbird 115.3.1
MFSA 2023-45 (bsc#1215814)
  * CVE-2023-5217 (bmo#1855550)
    Heap buffer overflow in libvpx
- Add mozilla-bmo1846703.patch

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=723
2023-09-29 20:44:41 +00:00
Wolfgang Rosenauer
70c5946a5c - Mozilla Thunderbird 115.3.0
https://www.thunderbird.net/en-US/thunderbird/115.3.0/releasenotes
  MFSA 2023-43 (bsc#1215575)
  * CVE-2023-5168 (bmo#1846683)
    Out-of-bounds write in FilterNodeD2D1
  * CVE-2023-5169 (bmo#1846685)
    Out-of-bounds write in PathOps
  * CVE-2023-5171 (bmo#1851599)
    Use-after-free in Ion Compiler
  * CVE-2023-5174 (bmo#1848454)
    Double-free in process spawning on Windows
  * CVE-2023-5176 (bmo#1836353, bmo#1842674, bmo#1843824,
    bmo#1843962, bmo#1848890, bmo#1850180, bmo#1850983,
    bmo#1851195)
    Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3,
    and Thunderbird 115.3

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=721
2023-09-27 09:43:36 +00:00
Wolfgang Rosenauer
d383915fad - Mozilla Thunderbird 115.2.3
Bugfix release:
  https://www.thunderbird.net/en-US/thunderbird/115.2.3/releasenotes

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=719
2023-09-21 06:48:37 +00:00
Wolfgang Rosenauer
a81e9b4cb4 Accepting request 1110766 from home:AndreasStieger:branches:mozilla:Factory
Mozilla Thunderbird 115.2.2 bsc#1215231

OBS-URL: https://build.opensuse.org/request/show/1110766
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=717
2023-09-12 21:29:55 +00:00
Wolfgang Rosenauer
45ef0c0c50 mozilla-bmo1775202.patch
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=715
2023-09-07 11:34:15 +00:00
Wolfgang Rosenauer
98a8bbee26 - Mozilla Thunderbird 115.2.0
https://www.thunderbird.net/en-US/thunderbird/115.2.0/releasenotes
  MFSA 2023-38 (bsc#1214606)
  * CVE-2023-4573 (bmo#1846687)
    Memory corruption in IPC CanvasTranslator
  * CVE-2023-4574 (bmo#1846688)
    Memory corruption in IPC ColorPickerShownCallback
  * CVE-2023-4575 (bmo#1846689)
    Memory corruption in IPC FilePickerShownCallback
  * CVE-2023-4576 (bmo#1846694)
    Integer Overflow in RecordedSourceSurfaceCreation
  * CVE-2023-4577 (bmo#1847397)
    Memory corruption in JIT UpdateRegExpStatics
  * CVE-2023-4051 (bmo#1821884)
    Full screen notification obscured by file open dialog
  * CVE-2023-4578 (bmo#1839007)
    Error reporting methods in SpiderMonkey could have triggered
    an Out of Memory Exception
  * CVE-2023-4053 (bmo#1839079)
    Full screen notification obscured by external program
  * CVE-2023-4580 (bmo#1843046)
    Push notifications saved to disk unencrypted
  * CVE-2023-4581 (bmo#1843758)
    XLL file extensions were downloadable without warnings
  * CVE-2023-4582 (bmo#1773874)
    Buffer Overflow in WebGL glGetProgramiv
  * CVE-2023-4583 (bmo#1842030)
    Browsing Context potentially not cleared when closing Private
    Window
  * CVE-2023-4584 (bmo#1843968, bmo#1845205, bmo#1846080,

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=714
2023-08-31 07:59:41 +00:00
Wolfgang Rosenauer
da50d4ab72 - Mozilla Thunderbird 102.14.0
MFSA 2023-32 (bsc#1213746)
  * CVE-2023-4045 (bmo#1833876)
    Offscreen Canvas could have bypassed cross-origin restrictions
  * CVE-2023-4046 (bmo#1837686)
    Incorrect value used during WASM compilation
  * CVE-2023-4047 (bmo#1839073)
    Potential permissions request bypass via clickjacking
  * CVE-2023-4048 (bmo#1841368)
    Crash in DOMParser due to out-of-memory conditions
  * CVE-2023-4049 (bmo#1842658)
    Fix potential race conditions when releasing platform objects
  * CVE-2023-4050 (bmo#1843038)
    Stack buffer overflow in StorageManager
  * CVE-2023-4054 (bmo#1840777)
    Lack of warning when opening appref-ms files
  * CVE-2023-4055 (bmo#1782561)
    Cookie jar overflow caused unexpected cookie jar state
  * CVE-2023-4056 (bmo#1820587, bmo#1824634, bmo#1839235,
    bmo#1842325, bmo#1843847)
    Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1,
    Firefox ESR 102.14, Thunderbird 115.1, and Thunderbird 102.14

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=712
2023-08-03 04:29:56 +00:00
Wolfgang Rosenauer
a858e257a4 Accepting request 1101575 from home:AndreasStieger:branches:mozilla:Factory
boo#1213658   OCD

OBS-URL: https://build.opensuse.org/request/show/1101575
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=711
2023-07-31 18:28:50 +00:00
Wolfgang Rosenauer
c92ecfd31b - Mozilla Thunderbird 102.13.1
MFSA 2023-28
  * CVE-2023-3417 (bmo#1835582)
    File Extension Spoofing using the Text Direction Override Character

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=709
2023-07-26 07:30:19 +00:00
Wolfgang Rosenauer
a450a78f9c - Mozilla Thunderbird 102.13.0
* Upstream RNP version numbers now recognized as official in about:support
  MFSA 2023-24 (bsc#1212438)
  * CVE-2023-37201 (bmo#1826002)
    Use-after-free in WebRTC certificate generation
  * CVE-2023-37202 (bmo#1834711)
    Potential use-after-free from compartment mismatch in
    SpiderMonkey
  * CVE-2023-37207 (bmo#1816287)
    Fullscreen notification obscured
  * CVE-2023-37208 (bmo#1837675)
    Lack of warning when opening Diagcab files
  * CVE-2023-37211 (bmo#1832306, bmo#1834862, bmo#1835886,
    bmo#1836550, bmo#1837450)
    Memory safety bugs fixed in Firefox 115, Firefox ESR 102.13,
    and Thunderbird 102.13
- mozilla-llvm16.patch has been applied upstream, remove it here

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=707
2023-07-08 18:44:08 +00:00
Wolfgang Rosenauer
8ab03d7649 Accepting request 1091941 from home:AndreasStieger:branches:mozilla:Factory
Mozilla Thunderbird 102.12.0 bsc#1211922

OBS-URL: https://build.opensuse.org/request/show/1091941
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=705
2023-06-10 10:47:23 +00:00
Wolfgang Rosenauer
4055c03185 - Mozilla Thunderbird 102.11.2
* fixed POP3 regressions ins 102.11.1
  * https://www.thunderbird.net/en-US/thunderbird/102.11.2/releasenotes/
  Thunderbird 102.11.1
  * https://www.thunderbird.net/en-US/thunderbird/102.11.1/releasenotes/

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=703
2023-05-27 08:18:22 +00:00
Wolfgang Rosenauer
23380907bc - Mozilla Thunderbird 102.11.0
* https://www.thunderbird.net/en-US/thunderbird/102.11.0/releasenotes
  MFSA 2023-18 (bsc#1211175)
  * CVE-2023-32205 (bmo#1753339, bmo#1753341)
    Browser prompts could have been obscured by popups
  * CVE-2023-32206 (bmo#1824892)
    Crash in RLBox Expat driver
  * CVE-2023-32207 (bmo#1826116)
    Potential permissions request bypass via clickjacking
  * CVE-2023-32211 (bmo#1823379)
    Content process crash due to invalid wasm code
  * CVE-2023-32212 (bmo#1826622)
    Potential spoof due to obscured address bar
  * CVE-2023-32213 (bmo#1826666)
    Potential memory corruption in FileReader::DoReadData()
  * CVE-2023-32214 (bmo#1828716)
    Potential DoS via exposed protocol handlers
  * CVE-2023-32215 (bmo#1540883, bmo#1751943, bmo#1814856,
    bmo#1820210, bmo#1821480, bmo#1827019, bmo#1827024, bmo#1827144,
    bmo#1827359, bmo#1830186)
    Memory safety bugs fixed in Firefox 113 and Firefox ESR 102.11

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=701
2023-05-11 06:49:50 +00:00
Wolfgang Rosenauer
96ebf6f723 - Mozilla Thunderbird 102.10.1
* https://www.thunderbird.net/en-US/thunderbird/102.10.1/releasenotes

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=699
2023-04-28 10:10:31 +00:00
Wolfgang Rosenauer
376ac03b18 * New messages will automatically select S/MIME if configured and
OpenPGP is not
  * Calendar events with timezone America/Mexico_City incorrectly
    applied Daylight Savings Time
  MFSA 2023-15 (bsc#1210212)
  * CVE-2023-29531 (bmo#1794292)
    Out-of-bound memory access in WebGL on macOS
  * CVE-2023-29532 (bmo#1806394)
    Mozilla Maintenance Service Write-lock bypass
  * CVE-2023-29533 (bmo#1798219, bmo#1814597)
    Fullscreen notification obscured
  * MFSA-TMP-2023-0001 (bmo#1819244)
    Double-free in libwebp
  * CVE-2023-29535 (bmo#1820543)
    Potential Memory Corruption following Garbage Collector compaction
  * CVE-2023-29536 (bmo#1821959)
    Invalid free from JavaScript code
  * CVE-2023-0547 (bmo#1811298)
    Revocation status of S/Mime recipient certificates was not checked
  * CVE-2023-29479 (bmo#1824978)
    Hang when processing certain OpenPGP messages
  * CVE-2023-29539 (bmo#1784348)
    Content-Disposition filename truncation leads to Reflected
    File Download
  * CVE-2023-29541 (bmo#1810191)
    Files with malicious extensions could have been downloaded
    unsafely on Linux
  * CVE-2023-29542 (bmo#1810793, bmo#1815062)
    Bypass of file download extension restrictions
  * CVE-2023-29545 (bmo#1823077)

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=697
2023-04-11 20:58:19 +00:00
Wolfgang Rosenauer
7a75a56779 - Mozilla Thunderbird 102.10.0
- add mozilla-llvm16.patch trying to fix build with LLVM16

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=696
2023-04-06 13:55:17 +00:00
Wolfgang Rosenauer
b695ba5251 - Mozilla Thunderbird 102.9.1
MFSA 2023-12
  * CVE-2023-28427 (bmo#1822595)
    Matrix SDK bundled with Thunderbird vulnerable to
    denial-of-service attack

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=695
2023-03-29 12:48:43 +00:00
Wolfgang Rosenauer
3d74973d59 - add gcc13-fix.patch to support current Tumbleweed
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=693
2023-03-26 16:31:37 +00:00
Wolfgang Rosenauer
b8ddf94b52 - build using rust 1.67
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=691
2023-03-16 13:11:48 +00:00
Wolfgang Rosenauer
34b61a3e8e - Mozilla Thunderbird 102.9.0
* https://www.thunderbird.net/en-US/thunderbird/102.9.0/releasenotes
  MFSA 2023-11 (bsc#1209173))
  * CVE-2023-25751 (bmo#1814899)
    Incorrect code generation during JIT compilation
  * CVE-2023-28164 (bmo#1809122)
    URL being dragged from a removed cross-origin iframe into the
    same tab triggered navigation
  * CVE-2023-28162 (bmo#1811327)
    Invalid downcast in Worklets
  * CVE-2023-25752 (bmo#1811627)
    Potential out-of-bounds when accessing throttled streams
  * CVE-2023-28163 (bmo#1817768)
    Windows Save As dialog resolved environment variables
  * CVE-2023-28176 (bmo#1808352, bmo#1811637, bmo#1815904,
    bmo#1817442, bmo#1818674)
    Memory safety bugs fixed in Thunderbird 102.9
- update create-tar.sh

- Ensure gcc11-c++ gets used on Leap 15.5, too.

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=690
2023-03-16 10:35:50 +00:00
Wolfgang Rosenauer
7e7b48d551 - Mozilla Thunderbird 102.8.0
* https://www.thunderbird.net/en-US/thunderbird/102.8.0/releasenotes
  MFSA 2023-07 (bsc#1208144)
  * CVE-2023-0616 (bmo#1806507)
    User Interface lockup with messages combining S/MIME and OpenPGP
  * CVE-2023-25728 (bmo#1790345)
    Content security policy leak in violation reports using iframes
  * CVE-2023-25730 (bmo#1794622)
    Screen hijack via browser fullscreen mode
  * CVE-2023-0767 (bmo#1804640)
    Arbitrary memory write via PKCS 12 in NSS
  * CVE-2023-25735 (bmo#1810711)
    Potential use-after-free from compartment mismatch in SpiderMonkey
  * CVE-2023-25737 (bmo#1811464)
    Invalid downcast in SVGUtils::SetupStrokeGeometry
  * CVE-2023-25738 (bmo#1811852)
    Printing on Windows could potentially crash Thunderbird with
    some device drivers
  * CVE-2023-25739 (bmo#1811939)
    Use-after-free in mozilla::dom::ScriptLoadContext::~ScriptLoadContext
  * CVE-2023-25729 (bmo#1792138)
    Extensions could have opened external schemes without user knowledge
  * CVE-2023-25732 (bmo#1804564)
    Out of bounds memory write from EncodeInputStream
  * CVE-2023-25734 (bmo#1784451, bmo#1809923, bmo#1810143, bmo#1812338)
    Opening local .url files could cause unexpected network loads
  * CVE-2023-25742 (bmo#1813424)
    Web Crypto ImportKey crashes tab
  * CVE-2023-25746 (bmo#1544127, bmo#1762368, bmo#1789449, bmo#1803628,
    bmo#1810536)

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=688
2023-02-19 09:41:40 +00:00
Wolfgang Rosenauer
c38dd3ccb4 - Mozilla Thunderbird 102.7.2
* Various crash fixes

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=686
2023-02-08 08:58:24 +00:00
Wolfgang Rosenauer
2f400cc863 - Mozilla Thunderbird 102.7.1
* Microsoft Office 365 accounts were unable to authenticate
  * https://www.thunderbird.net/en-US/thunderbird/102.7.1/releasenotes/
  MFSA 2023-04
  * CVE-2023-0430 (bmo#1769000)
    Revocation status of S/Mime signature certificates was not checked
- update create-tar.sh

- Mozilla Thunderbird 102.7.0
  https://www.thunderbird.net/en-US/thunderbird/102.7.0/releasenotes/
  MFSA 2023-03 (bsc#1207119)
  * CVE-2022-46871 (bmo#1795697)
    libusrsctp library out of date
  * CVE-2023-23598 (bmo#1800425)
    Arbitrary file read from GTK drag and drop on Linux
  * CVE-2023-23599 (bmo#1777800)
    Malicious command could be hidden in devtools output on
    Windows
  * CVE-2023-23601 (bmo#1794268)
    URL being dragged from cross-origin iframe into same tab
    triggers navigation
  * CVE-2023-23602 (bmo#1800890)
    Content Security Policy wasn't being correctly applied to
    WebSockets in WebWorkers
  * CVE-2022-46877 (bmo#1795139)
    Fullscreen notification bypass
  * CVE-2023-23603 (bmo#1800832)
    Calls to <code>console.log</code> allowed bypasing Content
    Security Policy via format directive
  * CVE-2023-23605 (bmo#1764921, bmo#1802690, bmo#1806974)

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=684
2023-02-01 07:54:38 +00:00
Wolfgang Rosenauer
6d02f7716c - Mozilla Thunderbird 102.6.1
* Remote content did not load in user-defined signatures
  * Addons that added new action buttons were not shown for addon
    upgrades, requiring removal and reinstall
  * Various stability improvements
  MFSA 2022-54
  * CVE-2022-46874 (bmo#1746139)
    Drag and Dropped Filenames could have been truncated to
    malicious extensions

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=682
2022-12-22 07:44:57 +00:00
Wolfgang Rosenauer
16ebad9cce - Mozilla Thunderbird 102.6.0
https://www.thunderbird.net/en-US/thunderbird/102.6.0/releasenotes/
  MFSA 2022-53 (bsc#1206242)
  * CVE-2022-46880 (bmo#1749292)
    Use-after-free in WebGL
  * CVE-2022-46872 (bmo#1799156)
    Arbitrary file read from a compromised content process
  * CVE-2022-46881 (bmo#1770930)
    Memory corruption in WebGL
  * CVE-2022-46874 (bmo#1746139)
    Drag and Dropped Filenames could have been truncated to
    malicious extensions
  * CVE-2022-46875 (bmo#1786188)
    Download Protections were bypassed by .atloc and .ftploc
    files on Mac OS
  * CVE-2022-46882 (bmo#1789371)
    Use-after-free in WebGL
  * CVE-2022-46878 (bmo#1782219, bmo#1797370, bmo#1797685,
    bmo#1801102, bmo#1801315, bmo#1802395)
    Memory safety bugs fixed in Thunderbird 102.6
- removed obsolete patches
  mozilla-newer-cbindgen.patch
  mozilla-glibc236.patch

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=680
2022-12-13 21:35:47 +00:00
Wolfgang Rosenauer
8e5a394a01 - Mozilla Thunderbird 102.5.1
MFSA 2022-50
  * CVE-2022-45414 (bmo#1788096)
    Quoting from an HTML email with certain tags will trigger network
    requests and load remote content, regardless of a configuration
    to block remote content

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=678
2022-12-01 21:40:36 +00:00
Wolfgang Rosenauer
d0799f3ab3 - Mozilla Thunderbird 102.5.0
* changes and fixes as described here
    https://www.thunderbird.net/en-US/thunderbird/102.5.0/releasenotes
  MFSA 2022-49 (bsc#1205270)
  * CVE-2022-45403 (bmo#1762078)
    Service Workers might have learned size of cross-origin media files
  * CVE-2022-45404 (bmo#1790815)
    Fullscreen notification bypass
  * CVE-2022-45405 (bmo#1791314)
    Use-after-free in InputStream implementation
  * CVE-2022-45406 (bmo#1791975)
    Use-after-free of a JavaScript Realm
  * CVE-2022-45408 (bmo#1793829)
    Fullscreen notification bypass via windowName
  * CVE-2022-45409 (bmo#1796901)
    Use-after-free in Garbage Collection
  * CVE-2022-45410 (bmo#1658869)
    ServiceWorker-intercepted requests bypassed SameSite cookie policy
  * CVE-2022-45411 (bmo#1790311)
    Cross-Site Tracing was possible via non-standard override headers
  * CVE-2022-45412 (bmo#1791029)
    Symlinks may resolve to partially uninitialized buffers
  * CVE-2022-45416 (bmo#1793676)
    Keystroke Side-Channel Leakage
  * CVE-2022-45418 (bmo#1795815)
    Custom mouse cursor could have been drawn over browser UI
  * CVE-2022-45420 (bmo#1792643)
    Iframe contents could be rendered outside the iframe
  * CVE-2022-45421 (bmo#1767920, bmo#1789808, bmo#1794061)
    Memory safety bugs fixed in Thunderbird 102.5

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=676
2022-11-16 13:42:05 +00:00
Wolfgang Rosenauer
ed89d64079 - Mozilla Thunderbird 102.4.2
* "Address Book" button in Account Central will now create a
    CardDAV address book instead of a local address book
  * Bugfixes as described here
    https://www.thunderbird.net/en-US/thunderbird/102.4.2/releasenotes

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=674
2022-11-05 16:23:19 +00:00
Wolfgang Rosenauer
9e67c8336c - Mozilla Thunderbird 102.4.1
* Thunderbird will now catch and report errors parsing vCards
    that contain incorrectly formatted dates
  * Dynamic language switching did not update interface when switched
    to right-to-left languages
  * Custom header data was discarded after messages were saved as
    draft and reopened
  * -remote command line argument did not work, affecting integration
    with various applications such as LibreOffice
  * Messages received via some SMS-to-email services could not
    display images
  * VCards with nickname field set could not be edited
  * Some recurring events were missing from Agenda on first load
  * Download requests for remote ICS calendars incorrectly set
    "Accept" header to text/xml
  * Monthly events created on the 31st of a month with <30 days placed
    first occurrence 1-2 days after the beginning of the following month
  * Various visual and UX improvements

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=672
2022-10-26 20:45:06 +00:00
Wolfgang Rosenauer
0268b45410 MFSA 2022-46 (bsc#1203477)
* CVE-2022-42927 (bmo#1789128)
    Same-origin policy violation could have leaked cross-origin URLs
  * CVE-2022-42928 (bmo#1791520)
    Memory Corruption in JS Engine
  * CVE-2022-42929 (bmo#1789439)
    Denial of Service via window.print
  * CVE-2022-42932 (bmo#1789729, bmo#1791363, bmo#1792041)
    Memory safety bugs fixed in Firefox 106, Firefox ESR 102.4 and
    Thunderbird 102.4.0

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=670
2022-10-23 08:54:57 +00:00
Wolfgang Rosenauer
3e0fc541fd - Mozilla Thunderbird 102.4.0
https://www.thunderbird.net/en-US/thunderbird/102.4.0/releasenotes

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=668
2022-10-20 06:20:46 +00:00
Wolfgang Rosenauer
2d8a6701f6 - Mozilla Thunderbird 102.3.3
* Option added to show containing address book for a contact when
    using All Address Books in vertical mode
  * Thunderbird will try to use POP NTLM authentication even if
    not advertised by server
  * Task List and Today Pane sidebars will no longer load when not visible
  * bugfixes as documented here
    https://www.thunderbird.net/en-US/thunderbird/102.3.3/releasenotes

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=666
2022-10-12 12:12:47 +00:00
Wolfgang Rosenauer
2465bafb74 - Mozilla Thunderbird 102.3.2
* Thunderbird will try to use POP CRAM-MD5 authentication even if
    not advertised by server
  * more bugfixes as in
    https://www.thunderbird.net/en-US/thunderbird/102.3.2/releasenotes

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=664
2022-10-09 07:59:44 +00:00
Wolfgang Rosenauer
a9ff5c5ba4 - build using rust 1.63
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=662
2022-10-03 14:41:37 +00:00
Wolfgang Rosenauer
87caf19955 - Mozilla Thunderbird 102.3.1
* Compose window encryption options now only appear for encryption
    technologies that have already been configured
  * Number of contacts in currently selected address book now
    displayed at bottom of Address Book list column
  Fixes
  * Password prompt did not include server hostname for POP servers
  * Edit Contact was missing from Contacts sidebar context menus
  * Address Book contact lists cut off display of some characters,
    the result being unreadable
  MFSA 2022-43
  * CVE-2022-39249 (bmo#1791765)
    Matrix SDK bundled with Thunderbird vulnerable to an
    impersonation attack by malicious server administrators
  * CVE-2022-39250 (bmo#1791765)
    Matrix SDK bundled with Thunderbird vulnerable to a device
    verification attack
  * CVE-2022-39251 (bmo#1791765)
    Matrix SDK bundled with Thunderbird vulnerable to an
    impersonation attack
  * CVE-2022-39236 (bmo#1791765)
    Matrix SDK bundled with Thunderbird vulnerable to a data
    corruption issue

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=660
2022-10-02 16:53:19 +00:00
Wolfgang Rosenauer
70aadd9160 MFSA 2022-42 (bsc#1203477)
* CVE-2022-40959 (bmo#1782211)
    Bypassing FeaturePolicy restrictions on transient pages
  * CVE-2022-40960 (bmo#1787633)
    Data-race when parsing non-UTF-8 URLs in threads
  * CVE-2022-40958 (bmo#1779993)
    Bypassing Secure Context restriction for cookies with __Host
    and __Secure prefix
  * CVE-2022-40956 (bmo#1770094)
    Content-Security-Policy base-uri bypass
  * CVE-2022-40957 (bmo#1777604)
    Incoherent instruction cache when building WASM on ARM64
  * CVE-2022-3155 (bmo#1789061)
    Attachment files saved to disk on macOS could be executed
    without warning
  * CVE-2022-40962 (bmo#1767360, bmo#1776655, bmo#1777574, bmo#1784835,
    bmo#1785109, bmo#1786502, bmo#1789440)
    Memory safety bugs fixed in Thunderbird 102.3

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=658
2022-09-21 21:04:50 +00:00
Wolfgang Rosenauer
b9d27af2da - Mozilla Thunderbird 102.3.0
https://www.thunderbird.net/en-US/thunderbird/102.3.0/releasenotes/
  * Thunderbird will no longer attempt to import account passwords
    when importing from another Thunderbird profile in order to
    prevent profile corruption and permanent data loss. (bmo#1790605)
  * Devtools performance profile will use Thunderbird presets
    instead of Web Developer presets (bmo#1785954)
  * Thunderbird startup performance improvements (bmo#1785967)
  * Saving email source and images failed (bmo#1777323, bmo#1778804)
  * Error message was shown repeatedly when temporary disk
    space was full (bmo#1788580)
  * Attaching OpenPGP keys without a set size to non-encrypted
    messages briefly displayed a size of zero bytes (bmo#1788952)
  * Global Search entry box initially contained "undefined" (bmo#1780963)
  * Delete from POP Server mail filter rule intermittently
    failed to trigger (bmo#1789418)
  * Connections to POP3 servers without UIDL support failed (bmo#1789314)
  * Pop accounts with "Fetch headers only" set downloaded complete
    messages if server did not advertise TOP capability (bmo#1789356)
  * "File -> New -> Address Book Contact" from Compose window did
    not work (bmo#1782418)
  * Attach "My vCard" option in compose window was not available
    (bmo#1787614)
  * Improved performance of matching a contact to an email address
    (bmo#1782725)
  * Address book only recognized a contact's first two email
    addresses (bmo#1777156)
  * Address book search and autocomplete failed if a contact vCard
    could not be parsed (bmo#1789793)
  * Downloading NNTP messages for offline use failed (bmo#1785773)

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=657
2022-09-20 21:03:11 +00:00
Wolfgang Rosenauer
247125c160 - Mozilla Thunderbird 102.2.2
https://www.thunderbird.net/en-US/thunderbird/102.2.2/releasenotes/
  * Setting added to change Calendar event double-click action to
    open Edit Event dialog rather than view only;
    Set calendar.events.defaultActionEdit to true
  * Running Compact Folders on maildir folders caused a redownload
    of all messages in the folder
  * Accessing mail folders in profiles with many folders was slow
  * SMTP servers were not always properly initialized, and were not
    listed in Account Settings
  * APOP authentication unsupported when connecting to POP3 server
  * OpenPGP key discovery failed
  * POP accounts hosted by AOL were not able to authenticate using OAuth2
  * Unable to open context menu in newsgroups header for groups
    that are not subscribed

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=655
2022-09-08 09:47:43 +00:00
Wolfgang Rosenauer
bff7539280 - Mozilla Thunderbird 102.2.1
MFSA 2022-38 (bsc#1203007)
  * CVE-2022-3033 (bmo#1784838)
    Leaking of sensitive information when composing a response to
    an HTML email with a META refresh tag
  * CVE-2022-3032 (bmo#1783831)
    Remote content specified in an HTML document that was nested
    inside an iframe's srcdoc attribute was not blocked
  * CVE-2022-3034 (bmo#1745751)
    An iframe element in an HTML email could trigger a network
    request
  * CVE-2022-36059 (bmo#1787741)
    Matrix SDK bundled with Thunderbird vulnerable to denial-of-
    service attack

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=653
2022-09-01 07:38:48 +00:00
Wolfgang Rosenauer
eba6cdf4f5 - Mozilla Thunderbird 102.2.0
* https://www.thunderbird.net/en-US/thunderbird/102.2.0/releasenotes/
  MFSA 2022-36 (bsc#1202645)
  * CVE-2022-38472 (bmo#1769155)
    Address bar spoofing via XSLT error handling
  * CVE-2022-38473 (bmo#1771685)
    Cross-origin XSLT Documents would have inherited the parent's
    permissions
  * CVE-2022-38476 (bmo#1760998)
    Data race and potential use-after-free in PK11_ChangePW
  * CVE-2022-38477 (bmo#1760611, bmo#1770219, bmo#1771159, bmo#1773363)
    Memory safety bugs fixed in Thunderbird 102.2
  * CVE-2022-38478 (bmo#1770630, bmo#1776658)
    Memory safety bugs fixed in Thunderbird 102.2, and
    Thunderbird 91.13
- disabled automatic usage of wayland because of known issues
  using MOZ_ENABLE_WAYLAND=1 in environment would still enable it
  (boo#1202606)

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=651
2022-08-26 06:39:36 +00:00
Wolfgang Rosenauer
e0d42a0cfd - added mozilla-glibc236.patch (bmo#1782988, boo#1202323)
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=649
2022-08-14 08:03:54 +00:00