14
0

Commit Graph

  • 5835378f85 - Mozilla Thunderbird 115.5.1 Bugfix release https://www.thunderbird.net/en-US/thunderbird/115.5.1/releasenotes * Advanced GnuPG keys may be protected with an unexpected passphrase * OpenPGP signatures rejected due to mismatched signature timestamp now display signature timestamp and clarifying message * Advanced address book search did not return results if display name was left blank * Clicking on attendee when inviting attendees added the attendee twice Wolfgang Rosenauer 2023-11-29 07:32:44 +00:00
  • 9e1f2838a9 Accepting request 1128271 from mozilla:Factory Ana Guerrero 2023-11-23 20:41:38 +00:00
  • 480e0302f0 MFSA 2023-52 (bsc#1217230) Wolfgang Rosenauer 2023-11-23 08:16:17 +00:00
  • 55bb2ec82a - Mozilla Thunderbird 115.5.0 https://www.thunderbird.net/en-US/thunderbird/115.5.0/releasenotes MFSA 2023-52 (bsc#) * CVE-2023-6204 (bmo#1841050) Out-of-bound memory access in WebGL2 blitFramebuffer * CVE-2023-6205 (bmo#1854076) Use-after-free in MessagePort::Entangled * CVE-2023-6206 (bmo#1857430) Clickjacking permission prompts using the fullscreen transition * CVE-2023-6207 (bmo#1861344) Use-after-free in ReadableByteStreamQueueEntry::Buffer * CVE-2023-6208 (bmo#1855345) Using Selection API would copy contents into X11 primary selection. * CVE-2023-6209 (bmo#1858570) Incorrect parsing of relative URLs starting with "///" * CVE-2023-6212 (bmo#1658432, bmo#1820983, bmo#1829252, bmo#1856072, bmo#1856091, bmo#1859030, bmo#1860943, bmo#1862782) Memory safety bugs fixed in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5 Wolfgang Rosenauer 2023-11-23 08:14:02 +00:00
  • bd0ee26f99 Accepting request 1126791 from mozilla:Factory Ana Guerrero 2023-11-16 19:28:43 +00:00
  • 328f51e3db - Mozilla Thunderbird 115.4.3 Bugfix release https://www.thunderbird.net/en-US/thunderbird/115.4.3/releasenotes Wolfgang Rosenauer 2023-11-16 09:04:06 +00:00
  • f1ace80360 Accepting request 1124229 from mozilla:Factory Ana Guerrero 2023-11-08 21:18:54 +00:00
  • 1bac4101c8 - Mozilla Thunderbird 115.4.2 https://www.thunderbird.net/en-US/thunderbird/115.4.2/releasenotes - build using rust/cargo 1.72 (1.69 about to be dropped from Factory) Wolfgang Rosenauer 2023-11-08 12:10:27 +00:00
  • 759308472e Accepting request 1120173 from mozilla:Factory Ana Guerrero 2023-10-25 16:03:34 +00:00
  • 62f65fe0ea - Mozilla Thunderbird 115.4.1 https://www.thunderbird.net/en-US/thunderbird/115.4.1/releasenotes https://www.thunderbird.net/en-US/thunderbird/115.4.0/releasenotes MFSA 2023-47 (bsc#1216338) * CVE-2023-5721 (bmo#1830820) Queued up rendering could have allowed websites to clickjack * CVE-2023-5732 (bmo#1690979, bmo#1836962) Address bar spoofing via bidirectional characters * CVE-2023-5724 (bmo#1836705) Large WebGL draw could have led to a crash * CVE-2023-5725 (bmo#1845739) WebExtensions could open arbitrary URLs * CVE-2023-5726 (bmo#1846205) Full screen notification obscured by file open dialog on macOS * CVE-2023-5727 (bmo#1847180) Download Protections were bypassed by .msix, .msixbundle, .appx, and .appxbundle files on Windows * CVE-2023-5728 (bmo#1852729) Improper object tracking during GC in the JavaScript engine could have led to a crash. * CVE-2023-5730 (bmo#1836607, bmo#1840918, bmo#1848694, bmo#1848833, bmo#1850191, bmo#1850259, bmo#1852596, bmo#1853201, bmo#1854002, bmo#1855306, bmo#1855640, bmo#1856695) Memory safety bugs fixed in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4.1 - removed obsolete mozilla-bmo1846703.patch Wolfgang Rosenauer 2023-10-25 06:36:45 +00:00
  • f4ecfaed93 Accepting request 1120115 from home:AndreasStieger:branches:mozilla:Factory Wolfgang Rosenauer 2023-10-24 21:00:55 +00:00
  • 5356bd4c50 Accepting request 1116802 from mozilla:Factory Ana Guerrero 2023-10-11 21:54:45 +00:00
  • 6c4666a6b7 - Mozilla Thunderbird 115.3.2 Bugfix release https://www.thunderbird.net/en-US/thunderbird/115.3.2/releasenotes Wolfgang Rosenauer 2023-10-11 06:35:40 +00:00
  • d9a56d1348 Accepting request 1114452 from mozilla:Factory Ana Guerrero 2023-10-01 19:22:40 +00:00
  • c1979ea7d9 - Mozilla Thunderbird 115.3.1 MFSA 2023-45 (bsc#1215814) * CVE-2023-5217 (bmo#1855550) Heap buffer overflow in libvpx - Add mozilla-bmo1846703.patch Wolfgang Rosenauer 2023-09-29 20:44:41 +00:00
  • 03bb18356b Accepting request 1113844 from mozilla:Factory Dominique Leuenberger 2023-09-27 22:25:51 +00:00
  • 70c5946a5c - Mozilla Thunderbird 115.3.0 https://www.thunderbird.net/en-US/thunderbird/115.3.0/releasenotes MFSA 2023-43 (bsc#1215575) * CVE-2023-5168 (bmo#1846683) Out-of-bounds write in FilterNodeD2D1 * CVE-2023-5169 (bmo#1846685) Out-of-bounds write in PathOps * CVE-2023-5171 (bmo#1851599) Use-after-free in Ion Compiler * CVE-2023-5174 (bmo#1848454) Double-free in process spawning on Windows * CVE-2023-5176 (bmo#1836353, bmo#1842674, bmo#1843824, bmo#1843962, bmo#1848890, bmo#1850180, bmo#1850983, bmo#1851195) Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3 Wolfgang Rosenauer 2023-09-27 09:43:36 +00:00
  • 263916113a Accepting request 1112694 from mozilla:Factory Ana Guerrero 2023-09-21 20:22:38 +00:00
  • d383915fad - Mozilla Thunderbird 115.2.3 Bugfix release: https://www.thunderbird.net/en-US/thunderbird/115.2.3/releasenotes Wolfgang Rosenauer 2023-09-21 06:48:37 +00:00
  • d485729260 Accepting request 1110767 from mozilla:Factory Ana Guerrero 2023-09-13 18:44:58 +00:00
  • a81e9b4cb4 Accepting request 1110766 from home:AndreasStieger:branches:mozilla:Factory Wolfgang Rosenauer 2023-09-12 21:29:55 +00:00
  • 9ff5d4a1b6 Accepting request 1109528 from mozilla:Factory Ana Guerrero 2023-09-07 19:13:51 +00:00
  • 45ef0c0c50 mozilla-bmo1775202.patch Wolfgang Rosenauer 2023-09-07 11:34:15 +00:00
  • 98a8bbee26 - Mozilla Thunderbird 115.2.0 https://www.thunderbird.net/en-US/thunderbird/115.2.0/releasenotes MFSA 2023-38 (bsc#1214606) * CVE-2023-4573 (bmo#1846687) Memory corruption in IPC CanvasTranslator * CVE-2023-4574 (bmo#1846688) Memory corruption in IPC ColorPickerShownCallback * CVE-2023-4575 (bmo#1846689) Memory corruption in IPC FilePickerShownCallback * CVE-2023-4576 (bmo#1846694) Integer Overflow in RecordedSourceSurfaceCreation * CVE-2023-4577 (bmo#1847397) Memory corruption in JIT UpdateRegExpStatics * CVE-2023-4051 (bmo#1821884) Full screen notification obscured by file open dialog * CVE-2023-4578 (bmo#1839007) Error reporting methods in SpiderMonkey could have triggered an Out of Memory Exception * CVE-2023-4053 (bmo#1839079) Full screen notification obscured by external program * CVE-2023-4580 (bmo#1843046) Push notifications saved to disk unencrypted * CVE-2023-4581 (bmo#1843758) XLL file extensions were downloadable without warnings * CVE-2023-4582 (bmo#1773874) Buffer Overflow in WebGL glGetProgramiv * CVE-2023-4583 (bmo#1842030) Browsing Context potentially not cleared when closing Private Window * CVE-2023-4584 (bmo#1843968, bmo#1845205, bmo#1846080, Wolfgang Rosenauer 2023-08-31 07:59:41 +00:00
  • f3bf95db38 Accepting request 1102113 from mozilla:Factory Dominique Leuenberger 2023-08-03 15:29:27 +00:00
  • da50d4ab72 - Mozilla Thunderbird 102.14.0 MFSA 2023-32 (bsc#1213746) * CVE-2023-4045 (bmo#1833876) Offscreen Canvas could have bypassed cross-origin restrictions * CVE-2023-4046 (bmo#1837686) Incorrect value used during WASM compilation * CVE-2023-4047 (bmo#1839073) Potential permissions request bypass via clickjacking * CVE-2023-4048 (bmo#1841368) Crash in DOMParser due to out-of-memory conditions * CVE-2023-4049 (bmo#1842658) Fix potential race conditions when releasing platform objects * CVE-2023-4050 (bmo#1843038) Stack buffer overflow in StorageManager * CVE-2023-4054 (bmo#1840777) Lack of warning when opening appref-ms files * CVE-2023-4055 (bmo#1782561) Cookie jar overflow caused unexpected cookie jar state * CVE-2023-4056 (bmo#1820587, bmo#1824634, bmo#1839235, bmo#1842325, bmo#1843847) Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1, Firefox ESR 102.14, Thunderbird 115.1, and Thunderbird 102.14 Wolfgang Rosenauer 2023-08-03 04:29:56 +00:00
  • a858e257a4 Accepting request 1101575 from home:AndreasStieger:branches:mozilla:Factory Wolfgang Rosenauer 2023-07-31 18:28:50 +00:00
  • 08933f69a0 Accepting request 1100766 from mozilla:Factory Ana Guerrero 2023-07-26 11:24:38 +00:00
  • c92ecfd31b - Mozilla Thunderbird 102.13.1 MFSA 2023-28 * CVE-2023-3417 (bmo#1835582) File Extension Spoofing using the Text Direction Override Character Wolfgang Rosenauer 2023-07-26 07:30:19 +00:00
  • fbaa0b6684 Accepting request 1097755 from mozilla:Factory Dominique Leuenberger 2023-07-09 18:39:07 +00:00
  • a450a78f9c - Mozilla Thunderbird 102.13.0 * Upstream RNP version numbers now recognized as official in about:support MFSA 2023-24 (bsc#1212438) * CVE-2023-37201 (bmo#1826002) Use-after-free in WebRTC certificate generation * CVE-2023-37202 (bmo#1834711) Potential use-after-free from compartment mismatch in SpiderMonkey * CVE-2023-37207 (bmo#1816287) Fullscreen notification obscured * CVE-2023-37208 (bmo#1837675) Lack of warning when opening Diagcab files * CVE-2023-37211 (bmo#1832306, bmo#1834862, bmo#1835886, bmo#1836550, bmo#1837450) Memory safety bugs fixed in Firefox 115, Firefox ESR 102.13, and Thunderbird 102.13 - mozilla-llvm16.patch has been applied upstream, remove it here Wolfgang Rosenauer 2023-07-08 18:44:08 +00:00
  • 545394691f Accepting request 1091973 from mozilla:Factory Dominique Leuenberger 2023-06-11 17:54:52 +00:00
  • 8ab03d7649 Accepting request 1091941 from home:AndreasStieger:branches:mozilla:Factory Wolfgang Rosenauer 2023-06-10 10:47:23 +00:00
  • 40c3790c5c Accepting request 1089289 from mozilla:Factory Dominique Leuenberger 2023-05-27 18:38:25 +00:00
  • 4055c03185 - Mozilla Thunderbird 102.11.2 * fixed POP3 regressions ins 102.11.1 * https://www.thunderbird.net/en-US/thunderbird/102.11.2/releasenotes/ Thunderbird 102.11.1 * https://www.thunderbird.net/en-US/thunderbird/102.11.1/releasenotes/ Wolfgang Rosenauer 2023-05-27 08:18:22 +00:00
  • 1fafb69c4a Accepting request 1086176 from mozilla:Factory Dominique Leuenberger 2023-05-11 10:33:56 +00:00
  • 23380907bc - Mozilla Thunderbird 102.11.0 * https://www.thunderbird.net/en-US/thunderbird/102.11.0/releasenotes MFSA 2023-18 (bsc#1211175) * CVE-2023-32205 (bmo#1753339, bmo#1753341) Browser prompts could have been obscured by popups * CVE-2023-32206 (bmo#1824892) Crash in RLBox Expat driver * CVE-2023-32207 (bmo#1826116) Potential permissions request bypass via clickjacking * CVE-2023-32211 (bmo#1823379) Content process crash due to invalid wasm code * CVE-2023-32212 (bmo#1826622) Potential spoof due to obscured address bar * CVE-2023-32213 (bmo#1826666) Potential memory corruption in FileReader::DoReadData() * CVE-2023-32214 (bmo#1828716) Potential DoS via exposed protocol handlers * CVE-2023-32215 (bmo#1540883, bmo#1751943, bmo#1814856, bmo#1820210, bmo#1821480, bmo#1827019, bmo#1827024, bmo#1827144, bmo#1827359, bmo#1830186) Memory safety bugs fixed in Firefox 113 and Firefox ESR 102.11 Wolfgang Rosenauer 2023-05-11 06:49:50 +00:00
  • 4d249b21a0 Accepting request 1083507 from mozilla:Factory Dominique Leuenberger 2023-04-28 14:24:28 +00:00
  • 96ebf6f723 - Mozilla Thunderbird 102.10.1 * https://www.thunderbird.net/en-US/thunderbird/102.10.1/releasenotes Wolfgang Rosenauer 2023-04-28 10:10:31 +00:00
  • b9156650b9 Accepting request 1078519 from mozilla:Factory Dominique Leuenberger 2023-04-12 10:51:34 +00:00
  • 376ac03b18 * New messages will automatically select S/MIME if configured and OpenPGP is not * Calendar events with timezone America/Mexico_City incorrectly applied Daylight Savings Time MFSA 2023-15 (bsc#1210212) * CVE-2023-29531 (bmo#1794292) Out-of-bound memory access in WebGL on macOS * CVE-2023-29532 (bmo#1806394) Mozilla Maintenance Service Write-lock bypass * CVE-2023-29533 (bmo#1798219, bmo#1814597) Fullscreen notification obscured * MFSA-TMP-2023-0001 (bmo#1819244) Double-free in libwebp * CVE-2023-29535 (bmo#1820543) Potential Memory Corruption following Garbage Collector compaction * CVE-2023-29536 (bmo#1821959) Invalid free from JavaScript code * CVE-2023-0547 (bmo#1811298) Revocation status of S/Mime recipient certificates was not checked * CVE-2023-29479 (bmo#1824978) Hang when processing certain OpenPGP messages * CVE-2023-29539 (bmo#1784348) Content-Disposition filename truncation leads to Reflected File Download * CVE-2023-29541 (bmo#1810191) Files with malicious extensions could have been downloaded unsafely on Linux * CVE-2023-29542 (bmo#1810793, bmo#1815062) Bypass of file download extension restrictions * CVE-2023-29545 (bmo#1823077) Wolfgang Rosenauer 2023-04-11 20:58:19 +00:00
  • 7a75a56779 - Mozilla Thunderbird 102.10.0 - add mozilla-llvm16.patch trying to fix build with LLVM16 Wolfgang Rosenauer 2023-04-06 13:55:17 +00:00
  • b695ba5251 - Mozilla Thunderbird 102.9.1 MFSA 2023-12 * CVE-2023-28427 (bmo#1822595) Matrix SDK bundled with Thunderbird vulnerable to denial-of-service attack Wolfgang Rosenauer 2023-03-29 12:48:43 +00:00
  • 121088b5d4 Accepting request 1074474 from mozilla:Factory Dominique Leuenberger 2023-03-27 16:15:46 +00:00
  • 3d74973d59 - add gcc13-fix.patch to support current Tumbleweed Wolfgang Rosenauer 2023-03-26 16:31:37 +00:00
  • 596c12be2a Accepting request 1072474 from mozilla:Factory Dominique Leuenberger 2023-03-16 21:59:08 +00:00
  • b8ddf94b52 - build using rust 1.67 Wolfgang Rosenauer 2023-03-16 13:11:48 +00:00
  • 34b61a3e8e - Mozilla Thunderbird 102.9.0 * https://www.thunderbird.net/en-US/thunderbird/102.9.0/releasenotes MFSA 2023-11 (bsc#1209173)) * CVE-2023-25751 (bmo#1814899) Incorrect code generation during JIT compilation * CVE-2023-28164 (bmo#1809122) URL being dragged from a removed cross-origin iframe into the same tab triggered navigation * CVE-2023-28162 (bmo#1811327) Invalid downcast in Worklets * CVE-2023-25752 (bmo#1811627) Potential out-of-bounds when accessing throttled streams * CVE-2023-28163 (bmo#1817768) Windows Save As dialog resolved environment variables * CVE-2023-28176 (bmo#1808352, bmo#1811637, bmo#1815904, bmo#1817442, bmo#1818674) Memory safety bugs fixed in Thunderbird 102.9 - update create-tar.sh Wolfgang Rosenauer 2023-03-16 10:35:50 +00:00
  • acf3a2ecce Accepting request 1066604 from mozilla:Factory Dominique Leuenberger 2023-02-19 17:19:17 +00:00
  • 7e7b48d551 - Mozilla Thunderbird 102.8.0 * https://www.thunderbird.net/en-US/thunderbird/102.8.0/releasenotes MFSA 2023-07 (bsc#1208144) * CVE-2023-0616 (bmo#1806507) User Interface lockup with messages combining S/MIME and OpenPGP * CVE-2023-25728 (bmo#1790345) Content security policy leak in violation reports using iframes * CVE-2023-25730 (bmo#1794622) Screen hijack via browser fullscreen mode * CVE-2023-0767 (bmo#1804640) Arbitrary memory write via PKCS 12 in NSS * CVE-2023-25735 (bmo#1810711) Potential use-after-free from compartment mismatch in SpiderMonkey * CVE-2023-25737 (bmo#1811464) Invalid downcast in SVGUtils::SetupStrokeGeometry * CVE-2023-25738 (bmo#1811852) Printing on Windows could potentially crash Thunderbird with some device drivers * CVE-2023-25739 (bmo#1811939) Use-after-free in mozilla::dom::ScriptLoadContext::~ScriptLoadContext * CVE-2023-25729 (bmo#1792138) Extensions could have opened external schemes without user knowledge * CVE-2023-25732 (bmo#1804564) Out of bounds memory write from EncodeInputStream * CVE-2023-25734 (bmo#1784451, bmo#1809923, bmo#1810143, bmo#1812338) Opening local .url files could cause unexpected network loads * CVE-2023-25742 (bmo#1813424) Web Crypto ImportKey crashes tab * CVE-2023-25746 (bmo#1544127, bmo#1762368, bmo#1789449, bmo#1803628, bmo#1810536) Wolfgang Rosenauer 2023-02-19 09:41:40 +00:00
  • 2c2886161d Accepting request 1063880 from mozilla:Factory Dominique Leuenberger 2023-02-09 15:22:04 +00:00
  • c38dd3ccb4 - Mozilla Thunderbird 102.7.2 * Various crash fixes Wolfgang Rosenauer 2023-02-08 08:58:24 +00:00
  • b47fc1bbef Accepting request 1062396 from mozilla:Factory Dominique Leuenberger 2023-02-02 17:07:12 +00:00
  • 2f400cc863 - Mozilla Thunderbird 102.7.1 * Microsoft Office 365 accounts were unable to authenticate * https://www.thunderbird.net/en-US/thunderbird/102.7.1/releasenotes/ MFSA 2023-04 * CVE-2023-0430 (bmo#1769000) Revocation status of S/Mime signature certificates was not checked - update create-tar.sh Wolfgang Rosenauer 2023-02-01 07:54:38 +00:00
  • 45a06d9fa7 Accepting request 1044166 from mozilla:Factory Dominique Leuenberger 2022-12-23 09:20:59 +00:00
  • 6d02f7716c - Mozilla Thunderbird 102.6.1 * Remote content did not load in user-defined signatures * Addons that added new action buttons were not shown for addon upgrades, requiring removal and reinstall * Various stability improvements MFSA 2022-54 * CVE-2022-46874 (bmo#1746139) Drag and Dropped Filenames could have been truncated to malicious extensions Wolfgang Rosenauer 2022-12-22 07:44:57 +00:00
  • f53b7f67a3 Accepting request 1042791 from mozilla:Factory Dominique Leuenberger 2022-12-15 18:23:40 +00:00
  • 16ebad9cce - Mozilla Thunderbird 102.6.0 https://www.thunderbird.net/en-US/thunderbird/102.6.0/releasenotes/ MFSA 2022-53 (bsc#1206242) * CVE-2022-46880 (bmo#1749292) Use-after-free in WebGL * CVE-2022-46872 (bmo#1799156) Arbitrary file read from a compromised content process * CVE-2022-46881 (bmo#1770930) Memory corruption in WebGL * CVE-2022-46874 (bmo#1746139) Drag and Dropped Filenames could have been truncated to malicious extensions * CVE-2022-46875 (bmo#1786188) Download Protections were bypassed by .atloc and .ftploc files on Mac OS * CVE-2022-46882 (bmo#1789371) Use-after-free in WebGL * CVE-2022-46878 (bmo#1782219, bmo#1797370, bmo#1797685, bmo#1801102, bmo#1801315, bmo#1802395) Memory safety bugs fixed in Thunderbird 102.6 - removed obsolete patches mozilla-newer-cbindgen.patch mozilla-glibc236.patch Wolfgang Rosenauer 2022-12-13 21:35:47 +00:00
  • bda93eedba Accepting request 1039407 from mozilla:Factory Dominique Leuenberger 2022-12-02 12:12:40 +00:00
  • 8e5a394a01 - Mozilla Thunderbird 102.5.1 MFSA 2022-50 * CVE-2022-45414 (bmo#1788096) Quoting from an HTML email with certain tags will trigger network requests and load remote content, regardless of a configuration to block remote content Wolfgang Rosenauer 2022-12-01 21:40:36 +00:00
  • e387b3a5d8 Accepting request 1036233 from mozilla:Factory Dominique Leuenberger 2022-11-17 16:24:06 +00:00
  • d0799f3ab3 - Mozilla Thunderbird 102.5.0 * changes and fixes as described here https://www.thunderbird.net/en-US/thunderbird/102.5.0/releasenotes MFSA 2022-49 (bsc#1205270) * CVE-2022-45403 (bmo#1762078) Service Workers might have learned size of cross-origin media files * CVE-2022-45404 (bmo#1790815) Fullscreen notification bypass * CVE-2022-45405 (bmo#1791314) Use-after-free in InputStream implementation * CVE-2022-45406 (bmo#1791975) Use-after-free of a JavaScript Realm * CVE-2022-45408 (bmo#1793829) Fullscreen notification bypass via windowName * CVE-2022-45409 (bmo#1796901) Use-after-free in Garbage Collection * CVE-2022-45410 (bmo#1658869) ServiceWorker-intercepted requests bypassed SameSite cookie policy * CVE-2022-45411 (bmo#1790311) Cross-Site Tracing was possible via non-standard override headers * CVE-2022-45412 (bmo#1791029) Symlinks may resolve to partially uninitialized buffers * CVE-2022-45416 (bmo#1793676) Keystroke Side-Channel Leakage * CVE-2022-45418 (bmo#1795815) Custom mouse cursor could have been drawn over browser UI * CVE-2022-45420 (bmo#1792643) Iframe contents could be rendered outside the iframe * CVE-2022-45421 (bmo#1767920, bmo#1789808, bmo#1794061) Memory safety bugs fixed in Thunderbird 102.5 Wolfgang Rosenauer 2022-11-16 13:42:05 +00:00
  • f92ca0eef0 Accepting request 1033698 from mozilla:Factory Dominique Leuenberger 2022-11-06 11:41:50 +00:00
  • ed89d64079 - Mozilla Thunderbird 102.4.2 * "Address Book" button in Account Central will now create a CardDAV address book instead of a local address book * Bugfixes as described here https://www.thunderbird.net/en-US/thunderbird/102.4.2/releasenotes Wolfgang Rosenauer 2022-11-05 16:23:19 +00:00
  • 50fd6a6a10 Accepting request 1031395 from mozilla:Factory Dominique Leuenberger 2022-10-28 17:28:39 +00:00
  • 9e67c8336c - Mozilla Thunderbird 102.4.1 * Thunderbird will now catch and report errors parsing vCards that contain incorrectly formatted dates * Dynamic language switching did not update interface when switched to right-to-left languages * Custom header data was discarded after messages were saved as draft and reopened * -remote command line argument did not work, affecting integration with various applications such as LibreOffice * Messages received via some SMS-to-email services could not display images * VCards with nickname field set could not be edited * Some recurring events were missing from Agenda on first load * Download requests for remote ICS calendars incorrectly set "Accept" header to text/xml * Monthly events created on the 31st of a month with <30 days placed first occurrence 1-2 days after the beginning of the following month * Various visual and UX improvements Wolfgang Rosenauer 2022-10-26 20:45:06 +00:00
  • b18f74fe55 Accepting request 1030583 from mozilla:Factory Dominique Leuenberger 2022-10-24 09:12:46 +00:00
  • 0268b45410 MFSA 2022-46 (bsc#1203477) * CVE-2022-42927 (bmo#1789128) Same-origin policy violation could have leaked cross-origin URLs * CVE-2022-42928 (bmo#1791520) Memory Corruption in JS Engine * CVE-2022-42929 (bmo#1789439) Denial of Service via window.print * CVE-2022-42932 (bmo#1789729, bmo#1791363, bmo#1792041) Memory safety bugs fixed in Firefox 106, Firefox ESR 102.4 and Thunderbird 102.4.0 Wolfgang Rosenauer 2022-10-23 08:54:57 +00:00
  • 113b18ccaa Accepting request 1030125 from mozilla:Factory Dominique Leuenberger 2022-10-22 12:12:48 +00:00
  • 3e0fc541fd - Mozilla Thunderbird 102.4.0 https://www.thunderbird.net/en-US/thunderbird/102.4.0/releasenotes Wolfgang Rosenauer 2022-10-20 06:20:46 +00:00
  • 66a41ade77 Accepting request 1010277 from mozilla:Factory Dominique Leuenberger 2022-10-13 13:40:03 +00:00
  • 2d8a6701f6 - Mozilla Thunderbird 102.3.3 * Option added to show containing address book for a contact when using All Address Books in vertical mode * Thunderbird will try to use POP NTLM authentication even if not advertised by server * Task List and Today Pane sidebars will no longer load when not visible * bugfixes as documented here https://www.thunderbird.net/en-US/thunderbird/102.3.3/releasenotes Wolfgang Rosenauer 2022-10-12 12:12:47 +00:00
  • 86b78c782b Accepting request 1009070 from mozilla:Factory Fabian Vogt 2022-10-10 16:46:30 +00:00
  • 2465bafb74 - Mozilla Thunderbird 102.3.2 * Thunderbird will try to use POP CRAM-MD5 authentication even if not advertised by server * more bugfixes as in https://www.thunderbird.net/en-US/thunderbird/102.3.2/releasenotes Wolfgang Rosenauer 2022-10-09 07:59:44 +00:00
  • 9b58affb8c Accepting request 1007697 from mozilla:Factory Richard Brown 2022-10-04 18:37:03 +00:00
  • a9ff5c5ba4 - build using rust 1.63 Wolfgang Rosenauer 2022-10-03 14:41:37 +00:00
  • f059dfb3c3 Accepting request 1007573 from mozilla:Factory Dominique Leuenberger 2022-10-03 11:43:50 +00:00
  • 87caf19955 - Mozilla Thunderbird 102.3.1 * Compose window encryption options now only appear for encryption technologies that have already been configured * Number of contacts in currently selected address book now displayed at bottom of Address Book list column Fixes * Password prompt did not include server hostname for POP servers * Edit Contact was missing from Contacts sidebar context menus * Address Book contact lists cut off display of some characters, the result being unreadable MFSA 2022-43 * CVE-2022-39249 (bmo#1791765) Matrix SDK bundled with Thunderbird vulnerable to an impersonation attack by malicious server administrators * CVE-2022-39250 (bmo#1791765) Matrix SDK bundled with Thunderbird vulnerable to a device verification attack * CVE-2022-39251 (bmo#1791765) Matrix SDK bundled with Thunderbird vulnerable to an impersonation attack * CVE-2022-39236 (bmo#1791765) Matrix SDK bundled with Thunderbird vulnerable to a data corruption issue Wolfgang Rosenauer 2022-10-02 16:53:19 +00:00
  • 1f09b0b77d Accepting request 1005289 from mozilla:Factory Dominique Leuenberger 2022-09-23 12:14:26 +00:00
  • 70aadd9160 MFSA 2022-42 (bsc#1203477) * CVE-2022-40959 (bmo#1782211) Bypassing FeaturePolicy restrictions on transient pages * CVE-2022-40960 (bmo#1787633) Data-race when parsing non-UTF-8 URLs in threads * CVE-2022-40958 (bmo#1779993) Bypassing Secure Context restriction for cookies with __Host and __Secure prefix * CVE-2022-40956 (bmo#1770094) Content-Security-Policy base-uri bypass * CVE-2022-40957 (bmo#1777604) Incoherent instruction cache when building WASM on ARM64 * CVE-2022-3155 (bmo#1789061) Attachment files saved to disk on macOS could be executed without warning * CVE-2022-40962 (bmo#1767360, bmo#1776655, bmo#1777574, bmo#1784835, bmo#1785109, bmo#1786502, bmo#1789440) Memory safety bugs fixed in Thunderbird 102.3 Wolfgang Rosenauer 2022-09-21 21:04:50 +00:00
  • b9d27af2da - Mozilla Thunderbird 102.3.0 https://www.thunderbird.net/en-US/thunderbird/102.3.0/releasenotes/ * Thunderbird will no longer attempt to import account passwords when importing from another Thunderbird profile in order to prevent profile corruption and permanent data loss. (bmo#1790605) * Devtools performance profile will use Thunderbird presets instead of Web Developer presets (bmo#1785954) * Thunderbird startup performance improvements (bmo#1785967) * Saving email source and images failed (bmo#1777323, bmo#1778804) * Error message was shown repeatedly when temporary disk space was full (bmo#1788580) * Attaching OpenPGP keys without a set size to non-encrypted messages briefly displayed a size of zero bytes (bmo#1788952) * Global Search entry box initially contained "undefined" (bmo#1780963) * Delete from POP Server mail filter rule intermittently failed to trigger (bmo#1789418) * Connections to POP3 servers without UIDL support failed (bmo#1789314) * Pop accounts with "Fetch headers only" set downloaded complete messages if server did not advertise TOP capability (bmo#1789356) * "File -> New -> Address Book Contact" from Compose window did not work (bmo#1782418) * Attach "My vCard" option in compose window was not available (bmo#1787614) * Improved performance of matching a contact to an email address (bmo#1782725) * Address book only recognized a contact's first two email addresses (bmo#1777156) * Address book search and autocomplete failed if a contact vCard could not be parsed (bmo#1789793) * Downloading NNTP messages for offline use failed (bmo#1785773) Wolfgang Rosenauer 2022-09-20 21:03:11 +00:00
  • 14a3407ee3 Accepting request 1001927 from mozilla:Factory Dominique Leuenberger 2022-09-09 16:22:38 +00:00
  • 247125c160 - Mozilla Thunderbird 102.2.2 https://www.thunderbird.net/en-US/thunderbird/102.2.2/releasenotes/ * Setting added to change Calendar event double-click action to open Edit Event dialog rather than view only; Set calendar.events.defaultActionEdit to true * Running Compact Folders on maildir folders caused a redownload of all messages in the folder * Accessing mail folders in profiles with many folders was slow * SMTP servers were not always properly initialized, and were not listed in Account Settings * APOP authentication unsupported when connecting to POP3 server * OpenPGP key discovery failed * POP accounts hosted by AOL were not able to authenticate using OAuth2 * Unable to open context menu in newsgroups header for groups that are not subscribed Wolfgang Rosenauer 2022-09-08 09:47:43 +00:00
  • 61e1c5b9ce Accepting request 1000596 from mozilla:Factory Dominique Leuenberger 2022-09-02 19:56:12 +00:00
  • bff7539280 - Mozilla Thunderbird 102.2.1 MFSA 2022-38 (bsc#1203007) * CVE-2022-3033 (bmo#1784838) Leaking of sensitive information when composing a response to an HTML email with a META refresh tag * CVE-2022-3032 (bmo#1783831) Remote content specified in an HTML document that was nested inside an iframe's srcdoc attribute was not blocked * CVE-2022-3034 (bmo#1745751) An iframe element in an HTML email could trigger a network request * CVE-2022-36059 (bmo#1787741) Matrix SDK bundled with Thunderbird vulnerable to denial-of- service attack Wolfgang Rosenauer 2022-09-01 07:38:48 +00:00
  • 080375fd1c Accepting request 999347 from mozilla:Factory Dominique Leuenberger 2022-08-27 09:48:04 +00:00
  • eba6cdf4f5 - Mozilla Thunderbird 102.2.0 * https://www.thunderbird.net/en-US/thunderbird/102.2.0/releasenotes/ MFSA 2022-36 (bsc#1202645) * CVE-2022-38472 (bmo#1769155) Address bar spoofing via XSLT error handling * CVE-2022-38473 (bmo#1771685) Cross-origin XSLT Documents would have inherited the parent's permissions * CVE-2022-38476 (bmo#1760998) Data race and potential use-after-free in PK11_ChangePW * CVE-2022-38477 (bmo#1760611, bmo#1770219, bmo#1771159, bmo#1773363) Memory safety bugs fixed in Thunderbird 102.2 * CVE-2022-38478 (bmo#1770630, bmo#1776658) Memory safety bugs fixed in Thunderbird 102.2, and Thunderbird 91.13 - disabled automatic usage of wayland because of known issues using MOZ_ENABLE_WAYLAND=1 in environment would still enable it (boo#1202606) Wolfgang Rosenauer 2022-08-26 06:39:36 +00:00
  • 69e19b7b66 Accepting request 995033 from mozilla:Factory Dominique Leuenberger 2022-08-15 17:56:35 +00:00
  • e0d42a0cfd - added mozilla-glibc236.patch (bmo#1782988, boo#1202323) Wolfgang Rosenauer 2022-08-14 08:03:54 +00:00
  • 712dc6d84c Accepting request 993911 from mozilla:Factory Dominique Leuenberger 2022-08-10 15:12:30 +00:00
  • 134f09dee2 - Mozilla Thunderbird 102.1.2 * fix for bmo#1777765 (no POP download progress bar) was backed out from this release to address broken POP message download with Fetch headers only selected in Account Settings (bmo#1783552) Wolfgang Rosenauer 2022-08-09 06:35:46 +00:00
  • ae8a4c4f39 - Mozilla Thunderbird 102.1.1 Bugfixes: * https://www.thunderbird.net/en-US/thunderbird/102.1.1/releasenotes/ Wolfgang Rosenauer 2022-08-08 13:10:06 +00:00
  • 8400e239db Accepting request 992051 from mozilla:Factory Dominique Leuenberger 2022-08-03 19:16:01 +00:00
  • 32ed6a10bb - added mozilla-pgo.patch to fix LTO builds with gcc Wolfgang Rosenauer 2022-08-01 14:43:32 +00:00
  • 982c2db4ff - Mozilla Thunderbird 102.1.0 * https://www.thunderbird.net/en-US/thunderbird/102.1.0/releasenotes MFSA 2022-32 (bsc#1201758) * CVE-2022-36319 (bmo#1737722) Mouse Position spoofing with CSS transforms * CVE-2022-36318 (bmo#1771774) Directory indexes for bundled resources reflected URL parameters * CVE-2022-36314 (bmo#1773894) Opening local <code>.lnk</code> files could cause unexpected network loads * CVE-2022-2505 (bmo#1769739, bmo#1772824) Memory safety bugs fixed in Thunderbird 102.1 - added mozilla-newer-cbindgen.patch to fix build with rust-cbindgen >= 0.24 (and also require that for build) Wolfgang Rosenauer 2022-07-29 12:07:40 +00:00
  • ebc8727216 - Mozilla Thunderbird 102.0.3 Bugfixes as in * https://www.thunderbird.net/en-US/thunderbird/102.0.3/releasenotes/ Wolfgang Rosenauer 2022-07-21 12:15:56 +00:00
  • bc74d05987 Accepting request 985736 from mozilla:Factory Dominique Leuenberger 2022-06-30 11:17:57 +00:00
  • 08ffa63092 - Mozilla Thunderbird 91.11.0 * CLIENTID fix for bmo#1759197 in Thunderbird 91.8.1 did not work additional fix applied * "Save-As" attachment dialog did not have filename pre-populated MFSA 2022-26 (bsc#1200793) * CVE-2022-34479 (bmo#1745595) A popup window could be resized in a way to overlay the address bar with web content * CVE-2022-34470 (bmo#1765951) Use-after-free in nsSHistory * CVE-2022-34468 (bmo#1768537) CSP sandbox header without allow-scripts can be bypassed via retargeted javascript: URI * CVE-2022-2226 (bmo#1775441) An email with a mismatching OpenPGP signature date was accepted as valid * CVE-2022-34481 (bmo#1497246) Potential integer overflow in ReplaceElementsAt * CVE-2022-31744 (bmo#1757604) CSP bypass enabling stylesheet injection * CVE-2022-34472 (bmo#1770123) Unavailable PAC file resulted in OCSP requests being blocked * CVE-2022-34478 (bmo#1773717) Microsoft protocols can be attacked if a user accepts a prompt * CVE-2022-2200 (bmo#1771381) Undesired attributes could be set as part of prototype pollution * CVE-2022-34484 (bmo#1763634, bmo#1772651) Memory safety bugs fixed in Thunderbird 91.11 and Thunderbird 102 Wolfgang Rosenauer 2022-06-29 08:52:40 +00:00
  • 8e765242f8 Accepting request 980158 from mozilla:Factory Dominique Leuenberger 2022-06-01 15:34:24 +00:00
  • 5b920d1fa1 - Mozilla Thunderbird 91.10.0 * Various UX and theme improvements MFSA 2022-22 (bsc#1200027) * CVE-2022-31736 (bmo#1735923) Cross-Origin resource's length leaked * CVE-2022-31737 (bmo#1743767) Heap buffer overflow in WebGL * CVE-2022-31738 (bmo#1756388) Browser window spoof using fullscreen mode * CVE-2022-31739 (bmo#1765049) Attacker-influenced path traversal when saving downloaded files * CVE-2022-31740 (bmo#1766806) Register allocation problem in WASM on arm64 * CVE-2022-31741 (bmo#1767590) Uninitialized variable leads to invalid memory read * CVE-2022-1834 (bmo#1767816) Braille space character caused incorrect sender email to be shown for a digitally signed email * CVE-2022-31742 (bmo#1730434) Querying a WebAuthn token with a large number of allowCredential entries may have leaked cross-origin information * CVE-2022-31747 (bmo#1760765, bmo#1765610, bmo#1766283, bmo#1767365, bmo#1768559, bmo#1768734) Memory safety bugs fixed in Thunderbird 91.10 Wolfgang Rosenauer 2022-05-31 19:36:16 +00:00