Commit Graph

  • 2c48a8976d Accepting request 914797 from mozilla:Factory Dominique Leuenberger 2021-09-03 19:25:42 +0000
  • 588265dc9f Accepting request 914700 from home:AndreasStieger:branches:mozilla:Factory Wolfgang Rosenauer 2021-08-28 14:15:56 +0000
  • 961987d81a Accepting request 913013 from mozilla:Factory Dominique Leuenberger 2021-08-24 08:54:07 +0000
  • 4f499ffe4c OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=602 Wolfgang Rosenauer 2021-08-19 07:30:27 +0000
  • 4416d70412 MFSA 2021-37 (bsc#1189547) * CVE-2021-29991 (bmo#1724896) Header Splitting possible with HTTP/3 Responses Wolfgang Rosenauer 2021-08-19 07:29:26 +0000
  • 6c01889e00 - Mozilla Thunderbird 91.0.1 - appdate screenshot URL updated (by mailaender@opensuse.org) Wolfgang Rosenauer 2021-08-19 07:16:16 +0000
  • 3e12a2f698 Accepting request 912581 from home:Mailaender:branches:mozilla:Factory Wolfgang Rosenauer 2021-08-19 07:13:22 +0000
  • 410b652abf Accepting request 911495 from mozilla:Factory Richard Brown 2021-08-16 08:05:36 +0000
  • aff12d5e4e - Mozilla Thunderbird 78.13.0 * removed WeTransfer integration package (not supported by vendor any longer) MFSA 2021-35 (bsc#1188891) * CVE-2021-29986 (bmo#1696138) Race condition when resolving DNS names could have led to memory corruption * CVE-2021-29988 (bmo#1717922) Memory corruption as a result of incorrect style treatment * CVE-2021-29984 (bmo#1720031) Incorrect instruction reordering during JIT optimization * CVE-2021-29980 (bmo#1722204) Uninitialized memory in a canvas object could have led to memory corruption * CVE-2021-29985 (bmo#1722083) Use-after-free media channels * CVE-2021-29989 (bmo#1662676, bmo#1666184, bmo#1719178, bmo#1719998, bmo#1720568) Memory safety bugs fixed in Thunderbird 78.13 Wolfgang Rosenauer 2021-08-11 20:23:07 +0000
  • 17246a4625 Accepting request 906332 from mozilla:Factory Dominique Leuenberger 2021-07-17 21:36:24 +0000
  • 423bce9730 - Mozilla Thunderbird 78.12.0 MFSA 2021-30 (bsc#1188275) * CVE-2021-29969 (bmo#1682370) IMAP server responses sent by a MITM prior to STARTTLS could be processed * CVE-2021-29970 (bmo#1709976) Use-after-free in accessibility features of a document * CVE-2021-30547 (bmo#1715766) Out of bounds write in ANGLE * CVE-2021-29976 (bmo#1700895, bmo#1703334, bmo#1706910, bmo#1711576, bmo#1714391) Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12 Wolfgang Rosenauer 2021-07-14 16:25:33 +0000
  • ef973c8645 Accepting request 897289 from mozilla:Factory Dominique Leuenberger 2021-06-09 19:51:02 +0000
  • 8929208551 MFSA 2021-26 (bsc#1186696) * CVE-2021-29964 (bmo#1706501) Out of bounds-read when parsing a WM_COPYDATA message * CVE-2021-29967 (bmo#1602862, bmo#1703191, bmo#1703760, bmo#1704722, bmo#1706041) Memory safety bugs fixed in Thunderbird 78.11 Wolfgang Rosenauer 2021-06-03 21:22:55 +0000
  • 7c722ac821 - Mozilla Thunderbird 78.11.0 * OpenPGP could not be disabled for an account if a key was previously configured * Recipients were unable to decrypt some messages when the sender had changed the message encryption from OpenPGP to S/MIME * Contacts moved between CardDAV address books were not synced to the new server * CardDAV compatibility fixes for Google Contacts MFSA 2021- - renewed expired mozilla.keyring Wolfgang Rosenauer 2021-06-02 20:13:57 +0000
  • c697113980 Accepting request 895572 from home:AndreasStieger:branches:mozilla:Factory Wolfgang Rosenauer 2021-05-26 15:53:34 +0000
  • f86926c22f Accepting request 894215 from mozilla:Factory Dominique Leuenberger 2021-05-20 17:23:30 +0000
  • fee04cb440 - do not rely on nodejs10 anymore Wolfgang Rosenauer 2021-05-19 06:20:51 +0000
  • 1098870ada Accepting request 891142 from mozilla:Factory Dominique Leuenberger 2021-05-10 13:36:21 +0000
  • 7175336fc8 Accepting request 891138 from home:AndreasStieger:branches:mozilla:Factory Wolfgang Rosenauer 2021-05-06 21:30:17 +0000
  • a10a636fe5 Accepting request 886906 from mozilla:Factory Dominique Leuenberger 2021-04-23 15:49:56 +0000
  • a828691223 OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=587 Wolfgang Rosenauer 2021-04-20 08:00:07 +0000
  • 9e204516c2 - Mozilla Thunderbird 78.10.0 MFSA 2021-14 (bsc#1184960) * CVE-2021-23994 (bmo#1699077) Out of bound write due to lazy initialization * CVE-2021-23995 (bmo#1699835) Use-after-free in Responsive Design Mode * CVE-2021-23998 (bmo#1667456) Secure Lock icon could have been spoofed * CVE-2021-23961 (bmo#1677940) More internal network hosts could have been probed by a malicious webpage * CVE-2021-23999 (bmo#1691153) Blob URLs may have been granted additional privileges * CVE-2021-24002 (bmo#1702374) Arbitrary FTP command execution on FTP servers using an encoded URL * CVE-2021-29945 (bmo#1700690) Incorrect size computation in WebAssembly JIT could lead to null-reads * CVE-2021-29946 (bmo#1698503) Port blocking could be bypassed * CVE-2021-29948 (bmo#1692899) Race condition when reading from disk while verifying signatures - recommend libotr5 Wolfgang Rosenauer 2021-04-20 07:54:22 +0000
  • 3c71a97936 Accepting request 884316 from mozilla:Factory Dominique Leuenberger 2021-04-15 14:56:41 +0000
  • 74378bcda4 - Mozilla Thunderbird 78.9.1 * Support recipient aliases for OpenPGP encryption * The key and signature parts of the message security popup on a received message could not be selected for copy/paste * Various UX and theme improvements MFSA 2021-13 * CVE-2021-23991 (bmo#1673240) An attacker may use Thunderbird's OpenPGP key refresh mechanism to poison an existing key * MOZ-2021-23992 (bmo#1666236) A crafted OpenPGP key with an invalid user ID could be used to confuse the user * CVE-2021-23993 (bmo#1666360) Inability to send encrypted OpenPGP email after importing a crafted OpenPGP key Wolfgang Rosenauer 2021-04-10 16:21:27 +0000
  • b34c6168bf Accepting request 881213 from mozilla:Factory Richard Brown 2021-04-06 15:29:06 +0000
  • 9e317f3906 - Mozilla Thunderbird 78.9.0 * bugfixes: https://www.thunderbird.net/en-US/thunderbird/78.9.0/releasenotes MFSA 2021-12 (boo#1183942) * CVE-2021-23981 (bmo#1692832) Texture upload into an unbound backing buffer resulted in an out-of-bound read * MOZ-2021-0002 (bmo#1691547) Angle graphics library out of date * CVE-2021-23982 (bmo#1677046) Internal network hosts could have been probed by a malicious webpage * CVE-2021-23984 (bmo#1693664) Malicious extensions could have spoofed popup information * CVE-2021-23987 (bmo#1513519, bmo#1683439, bmo#1690169, bmo#1690718) Memory safety bugs fixed in Firefox 87 and Firefox ESR 78.9 - cleaned up and fixed mozilla.sh.in for wayland (boo#1177542) Wolfgang Rosenauer 2021-03-24 21:31:27 +0000
  • 8522010cf3 Accepting request 878160 from mozilla:Factory Dominique Leuenberger 2021-03-12 12:31:28 +0000
  • 6c5e0317ac - Mozilla Thunderbird 78.8.1 * several bugfixes and improvements * https://www.thunderbird.net/en-US/thunderbird/78.8.1/releasenotes/ - updated create-tar.sh (bsc#1182357) Wolfgang Rosenauer 2021-03-10 12:07:26 +0000
  • de34e0778d Accepting request 874775 from mozilla:Factory Richard Brown 2021-03-02 11:26:54 +0000
  • e40e7bf353 - Mozilla Thunderbird 78.8.0 * various bugfixes MFSA 2021-09 (bsc#1182614) * CVE-2021-23969 (bmo#1542194) Content Security Policy violation report could have contained the destination of a redirect * CVE-2021-23968 (bmo#1687342) Content Security Policy violation report could have contained the destination of a redirect * CVE-2021-23973 (bmo#1690976) MediaError message property could have leaked information about cross-origin resources * CVE-2021-23978 (bmo#786797, bmo#1682928, bmo#1687391, bmo#1687597) Memory safety bugs fixed in Firefox 86 and Firefox ESR 78.8 Wolfgang Rosenauer 2021-02-24 08:08:21 +0000
  • 8a643d313e Accepting request 869925 from mozilla:Factory Dominique Leuenberger 2021-02-11 11:47:28 +0000
  • b79bfbd3a5 - Mozilla Thunderbird 78.7.1 * CardDAV address books now support OAuth2 and Google Contacts * Thunderbird will no longer allow installation of addons that use legacy APIs Wolfgang Rosenauer 2021-02-05 22:43:35 +0000
  • 7b7254ef3f Accepting request 867009 from mozilla:Factory Dominique Leuenberger 2021-01-29 13:55:50 +0000
  • fa9e13d8e7 - Mozilla Thunderbird 78.7.0 MFSA 2021-05 (bsc#1181414) * CVE-2021-23953 (bmo#1683940) Cross-origin information leakage via redirected PDF requests * CVE-2021-23954 (bmo#1684020) Type confusion when using logical assignment operators in JavaScript switch statements * CVE-2020-15685 (bmo#1622640) IMAP Response Injection when using STARTTLS * CVE-2020-26976 (bmo#1674343) HTTPS pages could have been intercepted by a registered service worker when they should not have been * CVE-2021-23960 (bmo#1675755) Use-after-poison for incorrectly redeclared JavaScript variables during GC * CVE-2021-23964 (bmo#1662507, bmo#1666285, bmo#1673526, bmo#1674278, bmo#1674835, bmo#1675097, bmo#1675844, bmo#1675868, bmo#1677590, bmo#1677888, bmo#1680410, bmo#1681268, bmo#1682068, bmo#1682938, bmo#1683736, bmo#1685260, bmo#1685925) Memory safety bugs fixed in Thunderbird 78.7 Wolfgang Rosenauer 2021-01-26 21:46:33 +0000
  • 7af05402eb Accepting request 862980 from mozilla:Factory Dominique Leuenberger 2021-01-18 10:26:40 +0000
  • 5c0edfa8c6 revert previous change Wolfgang Rosenauer 2021-01-13 14:46:17 +0000
  • ff0ed7bc92 - Mozilla Thunderbird 78.6.1 MFSA 2021-02 (bsc#1180623) * CVE-2020-16044 (bmo#1683964) Use-after-free write when handling a malicious COOKIE-ECHO SCTP chunk Wolfgang Rosenauer 2021-01-11 22:06:38 +0000
  • 926af1b2b2 Accepting request 856497 from mozilla:Factory Dominique Leuenberger 2020-12-24 18:40:01 +0000
  • a88987f6eb do not touch buildroot in %build Wolfgang Rosenauer 2020-12-16 13:32:05 +0000
  • d604cb9fa9 - Mozilla Thunderbird 78.6.0 * changes and additions in MailExtensions * several bugfixes * https://www.thunderbird.net/en-US/thunderbird/78.6.0/releasenotes/ MFSA 2020-56 (bsc#1180039)) * CVE-2020-16042 (bmo#1679003) Operations on a BigInt could have caused uninitialized memory to be exposed * CVE-2020-26971 (bmo#1663466) Heap buffer overflow in WebGL * CVE-2020-26973 (bmo#1680084) CSS Sanitizer performed incorrect sanitization * CVE-2020-26974 (bmo#1681022) Incorrect cast of StyleGenericFlexBasis resulted in a heap use-after-free * CVE-2020-26978 (bmo#1677047) Internal network hosts could have been probed by a malicious webpage * CVE-2020-35111 (bmo#1657916) The proxy.onRequest API did not catch view-source URLs * CVE-2020-35112 (bmo#1661365) Opening an extension-less download may have inadvertently launched an executable instead * CVE-2020-35113 (bmo#1664831, bmo#1673589) Memory safety bugs fixed in Thunderbird 78.6 Wolfgang Rosenauer 2020-12-15 22:24:07 +0000
  • 354c7e608e Accepting request 852686 from mozilla:Factory Dominique Leuenberger 2020-12-04 20:26:18 +0000
  • b0432050ce - Mozilla Thunderbird 78.5.1 MFSA 2020-53 (bsc#1179530) * CVE-2020-26970 (bmo#1677338) Stack overflow due to incorrect parsing of SMTP server response codes Wolfgang Rosenauer 2020-12-02 16:28:42 +0000
  • 6cfd650c6b Accepting request 849310 from mozilla:Factory Dominique Leuenberger 2020-11-21 11:40:29 +0000
  • 4a95a320a3 - Mozilla Thunderbird 78.5.0 MFSA 2020-52 (bsc#1178894) * CVE-2020-26951 (bmo#1667113) Parsing mismatches could confuse and bypass security sanitizer for chrome privileged code * CVE-2020-16012 (bmo#1642028) Variable time processing of cross-origin images during drawImage calls * CVE-2020-26953 (bmo#1656741) Fullscreen could be enabled without displaying the security UI * CVE-2020-26956 (bmo#1666300) XSS through paste (manual and clipboard API) * CVE-2020-26958 (bmo#1669355) Requests intercepted through ServiceWorkers lacked MIME type restrictions * CVE-2020-26959 (bmo#1669466) Use-after-free in WebRequestService * CVE-2020-26960 (bmo#1670358) Potential use-after-free in uses of nsTArray * CVE-2020-15999 (bmo#1672223) Heap buffer overflow in freetype * CVE-2020-26961 (bmo#1672528) DoH did not filter IPv4 mapped IP Addresses * CVE-2020-26965 (bmo#1661617) Software keyboards may have remembered typed passwords * CVE-2020-26966 (bmo#1663571) Single-word search queries were also broadcast to local network * CVE-2020-26968 (bmo#1551615, bmo#1607762, bmo#1656697, Wolfgang Rosenauer 2020-11-17 14:20:30 +0000
  • 3a8fbb1470 Accepting request 847757 from mozilla:Factory Dominique Leuenberger 2020-11-15 14:21:12 +0000
  • 808637d07c https://www.thunderbird.net/en-US/thunderbird/78.4.3/releasenotes/ Wolfgang Rosenauer 2020-11-11 09:22:58 +0000
  • 007409f510 - Mozilla Thunderbird 78.4.3 - added mozilla-rust-1.47.patch to fix build with rust 1.47 Wolfgang Rosenauer 2020-11-11 09:21:39 +0000
  • db081d1533 - Mozilla Thunderbird 78.4.1 * Bugfixes and minor features https://www.thunderbird.net/en-US/thunderbird/78.4.1/releasenotes/ Wolfgang Rosenauer 2020-11-08 18:36:03 +0000
  • d7a7c5a683 Accepting request 843275 from mozilla:Factory Dominique Leuenberger 2020-10-26 15:08:16 +0000
  • 63df217471 MFSA 2020-47 (bsc#1177872) * CVE-2020-15969 (bmo#1666570) Use-after-free in usersctp * CVE-2020-15683 (bmo#1576843, bmo#1656987, bmo#1660954, bmo#1662760, bmo#1663439, bmo#1666140) Memory safety bugs fixed in Firefox 82 and Firefox ESR 78.4 Wolfgang Rosenauer 2020-10-21 20:18:32 +0000
  • 69e75a6f77 - Mozilla Thunderbird 78.4.0 * MailExtensions: browser.tabs.sendMessage API added * MailExtensions: messageDisplayScripts API added * Yahoo and AOL mail users using password authentication will be migrated to OAuth2 * MailExtensions: messageDisplay APIs extended to support multiple selected messages * MailExtensions: compose.begin functions now support creating a message with attachments * multiple bugfixes Wolfgang Rosenauer 2020-10-21 09:31:04 +0000
  • 7975166d69 Accepting request 842109 from mozilla:Factory Dominique Leuenberger 2020-10-20 14:01:45 +0000
  • 8d908f5892 - Mozilla Thunderbird 78.3.3 * OpenPGP: Improved support for encrypting with subkeys * OpenPGP message status icons were not visible in message header pane * OpenPGP Key Manager was missing from Tools menu on macOS * Creating a new calendar event did not require an event title - remove python2 dependencies for TW - support wayland mode/autodetection in startup wrapper - replace some Requires to use requires_ge macro where appropriate - improve langpack build (as already used for Firefox) - add ccache statistics output to build Wolfgang Rosenauer 2020-10-16 13:01:17 +0000
  • 3bdd2525c1 - remove python2 dependencies for Leap 15 and TW Wolfgang Rosenauer 2020-10-08 14:14:28 +0000
  • f92938469c Accepting request 840001 from mozilla:Factory Dominique Leuenberger 2020-10-08 11:09:58 +0000
  • 4a103ac86f - Mozilla Thunderbird 78.3.2 * OpenPGP: Improved support for encrypting with subkeys * OpenPGP: Encrypted messages with international characters were sometimes displayed incorrectly * Single-click deletion of recipient pills with middle mouse button restored * Searching an address book list did not display results * Dark mode, high contrast, and Windows theming fixes Wolfgang Rosenauer 2020-10-07 09:44:38 +0000
  • aa32e73753 Accepting request 838449 from mozilla:Factory Dominique Leuenberger 2020-10-03 16:55:52 +0000
  • 04ffbb1d9e - added platform patches: * mozilla-s390x-skia-gradient.patch * mozilla-pipewire-0-3.patch * mozilla-bmo1512162.patch * mozilla-bmo1626236.patch * mozilla-bmo998749.patch * mozilla-sandbox-fips.patch - removed obsolete platform patches * mozilla-s390-bigendian.patch * mozilla-nestegg-big-endian.patch * mozilla-openaes-decl.patch * mozilla-cubeb-noreturn.patch Wolfgang Rosenauer 2020-09-25 09:39:00 +0000
  • c90bbb3be9 - Mozilla Thunderbird 78.3.1 * fix crash in nsImapProtocol::CreateNewLineFromSocket (bmo#1667120) Wolfgang Rosenauer 2020-09-25 06:32:50 +0000
  • 7eb9850829 Accepting request 832601 from mozilla:Factory Dominique Leuenberger 2020-09-09 15:47:19 +0000
  • 85d782a0f4 - Mozilla Thunderbird 68.12.0 MFSA 2020-40 (bsc#1175686) * CVE-2020-15663 (bmo#1643199) Downgrade attack on the Mozilla Maintenance Service could have resulted in escalation of privilege * CVE-2020-15664 (bmo#1658214) Attacker-induced prompt for extension installation * CVE-2020-15669 (bmo#1656957) Use-After-Free when aborting an operation Wolfgang Rosenauer 2020-08-30 11:12:59 +0000
  • b774973e49 Accepting request 830280 from home:michel_mno:branches:mozilla:Factory Wolfgang Rosenauer 2020-08-30 11:02:29 +0000
  • bf3f1cf325 Accepting request 828128 from mozilla:Factory Dominique Leuenberger 2020-08-23 07:20:12 +0000
  • cfff8c3277 Accepting request 828067 from home:marxin:memory-constraint Wolfgang Rosenauer 2020-08-20 10:39:48 +0000
  • 6ff89622cd Accepting request 823878 from mozilla:Factory Dominique Leuenberger 2020-08-05 18:26:12 +0000
  • 17467a5a91 Accepting request 823877 from home:AndreasStieger:branches:mozilla:Factory Wolfgang Rosenauer 2020-08-01 11:37:02 +0000
  • 11aeb7fac9 Accepting request 823875 from home:AndreasStieger:branches:mozilla:Factory Wolfgang Rosenauer 2020-08-01 11:17:36 +0000
  • 5e753c676b Accepting request 818251 from mozilla:Factory Dominique Leuenberger 2020-07-06 14:14:16 +0000
  • 8146a35a9e Accepting request 818183 from home:AndreasStieger:branches:mozilla:Factory Wolfgang Rosenauer 2020-07-02 06:27:27 +0000
  • 69737b701e Accepting request 813558 from mozilla:Factory Dominique Leuenberger 2020-06-14 16:15:05 +0000
  • e65691f980 - updated create-tar.sh Wolfgang Rosenauer 2020-06-11 15:01:14 +0000
  • 623455131b - build with nodejs10 to be able to drop nodejs8 from TW Wolfgang Rosenauer 2020-06-11 14:54:15 +0000
  • 7a3d6901f5 Accepting request 812112 from mozilla:Factory Dominique Leuenberger 2020-06-08 21:57:56 +0000
  • cde3667d7c Accepting request 812111 from home:AndreasStieger:branches:mozilla:Factory Wolfgang Rosenauer 2020-06-06 22:07:29 +0000
  • f545cc667e Accepting request 808609 from mozilla:Factory Yuchen Lin 2020-05-28 07:09:41 +0000
  • 52917cea5c Accepting request 808559 from home:AndreasStieger:branches:mozilla:Factory Wolfgang Rosenauer 2020-05-25 06:47:34 +0000
  • f9bbc6bdab Accepting request 800587 from mozilla:Factory Dominique Leuenberger 2020-05-07 15:51:25 +0000
  • a8238222fd OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=530 Wolfgang Rosenauer 2020-05-06 07:27:49 +0000
  • 472726a884 * Account Manager fixes and improvements * https://www.thunderbird.net/en-US/thunderbird/68.8.0/releasenotes MFSA 2020-18 (bsc#1171186) * CVE-2020-12397 (bmo#1617370) Sender Email Address Spoofing using encoded Unicode characters * CVE-2020-12387 (bmo#1545345) Use-after-free during worker shutdown * CVE-2020-6831 (bmo#1632241) Buffer overflow in SCTP chunk input validation * CVE-2020-12392 (bmo#1614468) Arbitrary local file access with 'Copy as cURL' * CVE-2020-12393 (bmo#1615471) Devtools' 'Copy as cURL' feature did not fully escape website-controlled data, potentially leading to command injection * CVE-2020-12395 (bmo#1595886, bmo#1611482, bmo#1614704, bmo#1624098, bmo#1625749, bmo#1626382, bmo#1628076, bmo#1631508) Memory safety bugs fixed in Thunderbird 68.8.0 - removed obsolete patch mozilla-bmo1580963.patch (bmo#1580963) In general, these flaws cannot be exploited through email in Wolfgang Rosenauer 2020-05-06 07:22:35 +0000
  • f31294e41a - Mozilla Thunderbird 68.8.0 - Add mozilla-bmo1580963.patch to fix build with rust 1.43 Wolfgang Rosenauer 2020-05-05 07:51:42 +0000
  • 34187271c9 Accepting request 800249 from home:namtrac:branches:mozilla:Factory Wolfgang Rosenauer 2020-05-05 07:28:14 +0000
  • ccc9188360 Accepting request 793242 from mozilla:Factory Dominique Leuenberger 2020-04-15 17:52:17 +0000
  • 12132f7191 Accepting request 793228 from home:AndreasStieger:branches:mozilla:Factory Wolfgang Rosenauer 2020-04-11 21:13:39 +0000
  • 8f09505c5b Accepting request 792897 from home:AndreasStieger:branches:mozilla:Factory Wolfgang Rosenauer 2020-04-10 08:30:57 +0000
  • 15eff75ea5 Accepting request 787142 from mozilla:Factory Dominique Leuenberger 2020-03-24 21:31:06 +0000
  • 56310e4a94 - Mozilla Thunderbird 68.6.0 MFSA 2020-10 (bsc#1166238) * CVE-2020-6805 (bmo#1610880) Use-after-free when removing data about origins * CVE-2020-6806 (bmo#1612308) BodyStream::OnInputStreamReady was missing protections against state confusion * CVE-2020-6807 (bmo#1614971) Use-after-free in cubeb during stream destruction * CVE-2020-6811 (bmo#1607742) Devtools' 'Copy as cURL' feature did not fully escape website-controlled data, potentially leading to command injection * CVE-2019-20503 (bmo#1613765) Out of bounds reads in sctp_load_addresses_from_init * CVE-2020-6812 (bmo#1616661) The names of AirPods with personally identifiable information were exposed to websites with camera or microphone permission * CVE-2020-6814 (bmo#1592078, bmo#1604847, bmo#1608256, bmo#1612636, bmo#1614339) Memory safety bugs fixed in Thunderbird 68.6 - requires NSS >= 3.44.3 Wolfgang Rosenauer 2020-03-14 13:26:42 +0000
  • 1afcee9271 Accepting request 773527 from mozilla:Factory Oliver Kurz 2020-02-14 15:23:55 +0000
  • b44fdf6e1e - Mozilla Thunderbird 68.5.0 New * Support for Client Identity IMAP/SMTP Service Extension * Support for OAuth 2.0 authentication for POP3 accounts Fixes * Status area goes blank during account setup * Calendar: Could not remove color for default categories * Calendar: Prevent calendar component loading multiple times * Calendar: Today pane did not retain width between sessions MFSA 2020-07 (bsc#1163368) * CVE-2020-6793 (bmo#1608539) Out-of-bounds read when processing certain email messages * CVE-2020-6794 (bmo#1606619) Setting a master password post-Thunderbird 52 does not delete unencrypted previously stored passwords * CVE-2020-6795 (bmo#1611105) Crash processing S/MIME messages with multiple signatures * CVE-2020-6797 (bmo#1596668) (Mac OSX only) Extensions granted downloads.open permission could open arbitrary applications on Mac OSX * CVE-2020-6798 (bmo#1602944) Incorrect parsing of template tag could result in JavaScript injection * CVE-2020-6792 (bmo#1609607) Message ID calculcation was based on uninitialized data * CVE-2020-6800 (bmo#1595786,bmo#1596706,bmo#1598543,bmo#1604851, bmo#1608580,bmo#1608785,bmo#1605777) Memory safety bugs fixed in Thunderbird 68.5 Wolfgang Rosenauer 2020-02-11 20:44:27 +0000
  • 41d44a95d8 Accepting request 769383 from mozilla:Factory Dominique Leuenberger 2020-02-06 12:06:03 +0000
  • 4f424022cb Accepting request 769375 from home:hellcp:branches:mozilla:Factory Wolfgang Rosenauer 2020-02-02 19:22:31 +0000
  • 8d496767d5 Accepting request 767881 from mozilla:Factory Dominique Leuenberger 2020-01-30 08:37:03 +0000
  • 88ea2f535a - Mozilla Thunderbird 68.4.2 * Calendar: Task and Event tree colours adjusted for the dark theme * Retrieval of S/MIME certificates from LDAP failed * Address-parsing crash on some IMAP servers when mail.imap.use_envelope_cmd is set * Incorrect forwarding of HTML messages caused SMTP servers to respond with a timeout * Calendar: Various parts of the calendar UI stopped working when a second Thunderbird window opened Wolfgang Rosenauer 2020-01-27 10:15:48 +0000
  • ad8ff75d18 Accepting request 763056 from mozilla:Factory Dominique Leuenberger 2020-01-14 19:57:48 +0000
  • c3ae989234 - removed obsolete patch mozilla-bmo1511604.patch - added mozilla-bmo1602730.patch to fix LE<->BE issues in the platform (bmo#1602730) Wolfgang Rosenauer 2020-01-11 08:43:34 +0000
  • 424175f38c MFSA 2020-04 (bsc#1160498, bsc#1160305) Wolfgang Rosenauer 2020-01-11 08:36:41 +0000
  • 5d0ef2ba91 - Mozilla Thunderbird 68.4.1 * Various improvements when setting up an account for a Microsoft Exchange server: Now offers IMAP/SMTP if available, better detection for Office 365 accounts; re-run configuration after password change Fixes: * After changing view layout, the message display pane showed garbled content under some circumstances * Various theme changes to achieve "pixel perfection": Unread icon, "no results" icon, paragraph format and font selector, background of folder summary tooltip * Tags were lost on messages in shared IMAP folders under some circumstances * Calendar: Event attendee dialog was not displayed correctly MFSA 2020-04 (bsc#1160498) * CVE-2019-17026 (bmo#1607443) IonMonkey type confusion with StoreElementHole and FallibleStoreElement * CVE-2019-17015 (bmo#1599005) Memory corruption in parent process during new content process initialization on Windows * CVE-2019-17016 (bmo#1599181) Bypass of @namespace CSS sanitization during pasting * CVE-2019-17017 (bmo#1603055) Type Confusion in XPCVariant.cpp * CVE-2019-17021 (bmo#1599008) Heap address disclosure in parent process during content process initialization on Windows * CVE-2019-17022 (bmo#1602843) CSS sanitization does not escape HTML tags * CVE-2019-17024 (bmo#1507180, bmo#1595470, bmo#1598605, bmo#1601826) Wolfgang Rosenauer 2020-01-10 15:53:07 +0000
  • e9c5824a54 Accepting request 759724 from mozilla:Factory Dominique Leuenberger 2019-12-30 12:48:52 +0000
  • 1c4a233447 - add mozilla-bmo1583471.patch to allow building with rust 1.39 Wolfgang Rosenauer 2019-12-27 17:27:22 +0000
  • 8e55c5b577 - Mozilla Thunderbird 68.3.1 * In dark theme unread messages no longer shown in blue to Bugfixes * Message navigation with backward and forward buttons did not work in some circumstances Wolfgang Rosenauer 2019-12-20 22:23:27 +0000
  • 82acc8435a Accepting request 758641 from home:AndreasStieger:branches:mozilla:Factory Wolfgang Rosenauer 2019-12-20 22:19:58 +0000