20
0

leap-16.0 code-o-o#leap/features#240 #1

Closed
lkocman wants to merge 23 commits from lkocman/MozillaThunderbird:leap-16.0 into leap-16.0

23 Commits

Author SHA256 Message Date
02b45382fb Accepting request 1298009 from mozilla:Factory
- Mozilla Thunderbird ESR 140.1.1
  Fixed
  * Users with attachments open in tabs saw an error on Thunderbird restart
  * Sending from unified or local folder failed if no default account was set
  * Delete button could remove attachment instead of message
  * Message list scrolled back when returning to mail tab after opening a message

OBS-URL: https://build.opensuse.org/request/show/1298009
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaThunderbird?expand=0&rev=369
2025-08-07 14:48:53 +00:00
Wolfgang Rosenauer
5257fb9ed3 - Mozilla Thunderbird ESR 140.1.1
Fixed
  * Users with attachments open in tabs saw an error on Thunderbird restart
  * Sending from unified or local folder failed if no default account was set
  * Delete button could remove attachment instead of message
  * Message list scrolled back when returning to mail tab after opening a message

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=833
2025-08-06 18:14:05 +00:00
24b8a7dd97 Accepting request 1297206 from mozilla:Factory
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/1297206
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaThunderbird?expand=0&rev=368
2025-08-03 11:38:21 +00:00
Wolfgang Rosenauer
b12070674d - Update memory constraints
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=831
2025-08-01 08:44:07 +00:00
842cecfac2 Accepting request 1295681 from mozilla:Factory
- Mozilla Thunderbird ESR 140.1.0
  * New folders were not added alphabetically if folders manually
    reordered beforehand
  * Message archive folder creation could silently stop during async
    folder creation
  MFSA 2025-63 (bsc#1246664)
  * CVE-2025-8027 (bmo#1968423)
    JavaScript engine only wrote partial return value to stack
  * CVE-2025-8028 (bmo#1971581)
    Large branch table could lead to truncated instruction
  * CVE-2025-8029 (bmo#1928021)
    javascript: URLs executed on object and embed tags
  * CVE-2025-8036 (bmo#1960834)
    DNS rebinding circumvents CORS
  * CVE-2025-8037 (bmo#1964767)
    Nameless cookies shadow secure cookies
  * CVE-2025-8030 (bmo#1968414)
    Potential user-assisted code execution in “Copy as cURL” command
  * CVE-2025-8031 (bmo#1971719)
    Incorrect URL stripping in CSP reports
  * CVE-2025-8032 (bmo#1974407)
    XSLT documents could bypass CSP
  * CVE-2025-8038 (bmo#1808979)
    CSP frame-src was not correctly enforced for paths
  * CVE-2025-8039 (bmo#1970997)
    Search terms persisted in URL bar
  * CVE-2025-8033 (bmo#1973990)
    Incorrect JavaScript state machine for generators
  * CVE-2025-8034 (bmo#1970422, bmo#1970422, bmo#1970422, bmo#1970422)
    Memory safety bugs fixed in Firefox ESR 115.26, Firefox ESR

OBS-URL: https://build.opensuse.org/request/show/1295681
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaThunderbird?expand=0&rev=367
2025-07-25 15:05:51 +00:00
Wolfgang Rosenauer
36e53452f3 - Mozilla Thunderbird ESR 140.1.0
* New folders were not added alphabetically if folders manually
    reordered beforehand
  * Message archive folder creation could silently stop during async
    folder creation
  MFSA 2025-63 (bsc#1246664)
  * CVE-2025-8027 (bmo#1968423)
    JavaScript engine only wrote partial return value to stack
  * CVE-2025-8028 (bmo#1971581)
    Large branch table could lead to truncated instruction
  * CVE-2025-8029 (bmo#1928021)
    javascript: URLs executed on object and embed tags
  * CVE-2025-8036 (bmo#1960834)
    DNS rebinding circumvents CORS
  * CVE-2025-8037 (bmo#1964767)
    Nameless cookies shadow secure cookies
  * CVE-2025-8030 (bmo#1968414)
    Potential user-assisted code execution in “Copy as cURL” command
  * CVE-2025-8031 (bmo#1971719)
    Incorrect URL stripping in CSP reports
  * CVE-2025-8032 (bmo#1974407)
    XSLT documents could bypass CSP
  * CVE-2025-8038 (bmo#1808979)
    CSP frame-src was not correctly enforced for paths
  * CVE-2025-8039 (bmo#1970997)
    Search terms persisted in URL bar
  * CVE-2025-8033 (bmo#1973990)
    Incorrect JavaScript state machine for generators
  * CVE-2025-8034 (bmo#1970422, bmo#1970422, bmo#1970422, bmo#1970422)
    Memory safety bugs fixed in Firefox ESR 115.26, Firefox ESR

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=829
2025-07-25 06:36:59 +00:00
d728693161 Accepting request 1290580 from mozilla:Factory
- Mozilla Thunderbird ESR 128.12.0
  MFSA 2025-55 (bsc#1244670)
  * CVE-2025-6424 (bmo#1966423)
    Use-after-free in FontFaceSet
  * CVE-2025-6425 (bmo#1717672)
    The WebCompat WebExtension shipped exposed a persistent UUID
  * CVE-2025-6426 (bmo#1964385)
    No warning when opening executable terminal files on macOS
  * CVE-2025-6429 (bmo#1970658)
    Incorrect parsing of URLs could have allowed embedding of
    youtube.com
  * CVE-2025-6430 (bmo#1971140)
    Content-Disposition header ignored when a file is included in
    an embed or object tag

OBS-URL: https://build.opensuse.org/request/show/1290580
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaThunderbird?expand=0&rev=366
2025-07-06 15:14:15 +00:00
Wolfgang Rosenauer
8cd0971e90 - Mozilla Thunderbird ESR 128.12.0
MFSA 2025-55 (bsc#1244670)
  * CVE-2025-6424 (bmo#1966423)
    Use-after-free in FontFaceSet
  * CVE-2025-6425 (bmo#1717672)
    The WebCompat WebExtension shipped exposed a persistent UUID
  * CVE-2025-6426 (bmo#1964385)
    No warning when opening executable terminal files on macOS
  * CVE-2025-6429 (bmo#1970658)
    Incorrect parsing of URLs could have allowed embedding of
    youtube.com
  * CVE-2025-6430 (bmo#1971140)
    Content-Disposition header ignored when a file is included in
    an embed or object tag

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=827
2025-07-04 05:55:54 +00:00
d0db3c1d44 Accepting request 1287471 from mozilla:Factory
- Use these tools/versions unconditionally, package won't build on
  Tumbleweed with new gcc15 otherwise:
  gcc14, gcc14-c++, cargo1.84, rust1.84

OBS-URL: https://build.opensuse.org/request/show/1287471
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaThunderbird?expand=0&rev=365
2025-06-23 13:01:39 +00:00
Wolfgang Rosenauer
3a8271f9c8 - Use these tools/versions unconditionally, package won't build on
Tumbleweed with new gcc15 otherwise:
  gcc14, gcc14-c++, cargo1.84, rust1.84

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=825
2025-06-20 20:58:10 +00:00
85783160a3 Accepting request 1284604 from mozilla:Factory
- Mozilla Thunderbird ESR 128.11.1
  MFSA 2025-49
  * CVE-2025-5986 (bmo#1958580, bmo#1968012)
    Unsolicited File Download, Disk Space Exhaustion, and Credential
    Leakage via mailbox:/// Links

- Replace usage of %jobs for reproducible builds (boo#1237231)

OBS-URL: https://build.opensuse.org/request/show/1284604
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaThunderbird?expand=0&rev=364
2025-06-11 14:24:54 +00:00
Wolfgang Rosenauer
28d3dfb87f - Mozilla Thunderbird ESR 128.11.1
MFSA 2025-49
  * CVE-2025-5986 (bmo#1958580, bmo#1968012)
    Unsolicited File Download, Disk Space Exhaustion, and Credential
    Leakage via mailbox:/// Links

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=823
2025-06-11 04:58:59 +00:00
Wolfgang Rosenauer
f41fa22c90 Accepting request 1283963 from home:bmwiedemann:branches:mozilla:Factory
Replace usage of %jobs for reproducible builds (boo#1237231)

OBS-URL: https://build.opensuse.org/request/show/1283963
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=822
2025-06-09 05:31:59 +00:00
4c3dd7fae5 Accepting request 1280770 from mozilla:Factory
OBS-URL: https://build.opensuse.org/request/show/1280770
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaThunderbird?expand=0&rev=363
2025-05-30 12:33:07 +00:00
Wolfgang Rosenauer
1f9d559ff5 128.11.0
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=820
2025-05-28 08:21:26 +00:00
e363e60cd3 Accepting request 1279281 from mozilla:Factory
OBS-URL: https://build.opensuse.org/request/show/1279281
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaThunderbird?expand=0&rev=362
2025-05-23 12:30:49 +00:00
Wolfgang Rosenauer
ae500f1db6 Accepting request 1279280 from home:AndreasStieger:branches:mozilla:Factory
fix mfsa

OBS-URL: https://build.opensuse.org/request/show/1279280
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=818
2025-05-22 13:10:09 +00:00
Wolfgang Rosenauer
61dba6b468 Accepting request 1279086 from home:AndreasStieger:branches:mozilla:Factory
changelog for Mozilla Thunderbird ESR 128.0.2

OBS-URL: https://build.opensuse.org/request/show/1279086
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=817
2025-05-21 17:05:16 +00:00
17738f3082 Accepting request 1277886 from mozilla:Factory
OBS-URL: https://build.opensuse.org/request/show/1277886
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaThunderbird?expand=0&rev=361
2025-05-20 07:33:34 +00:00
Wolfgang Rosenauer
fcd8a5b9c3 Mozilla Thunderbird ESR 128.10.1 boo#1243216
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=815
2025-05-15 19:26:08 +00:00
Wolfgang Rosenauer
854da840c2 - build on s390x needs 17G memory - adjust _constraints
OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=814
2025-05-12 05:50:10 +00:00
ce10049049 Accepting request 1273775 from mozilla:Factory
- Mozilla Thunderbird ESR 128.10.0
  * Changed color override defaults with high contrast mode on
    macOS and Linux
  * Using Delete column in "Search Messages..." window could delete
    other messages
  MFSA 2025-32 (bsc#1241621)
  * CVE-2025-2817 (bmo#1917536)
    Privilege escalation in Thunderbird Updater
  * CVE-2025-4082 (bmo#1937097)
    WebGL shader attribute memory corruption in Thunderbird for
    macOS
  * CVE-2025-4083 (bmo#1958350)
    Process isolation bypass using "javascript:" URI links in
    cross-origin frames
  * CVE-2025-4084 (bmo#1949994, bmo#1956698, bmo#1960198)
    Potential local code execution in "copy as cURL" command
  * CVE-2025-4087 (bmo#1952465)
    Unsafe attribute access during XPath parsing
  * CVE-2025-4091 (bmo#1951161, bmo#1952105)
    Memory safety bugs fixed in Firefox 138, Thunderbird 138,
    Firefox ESR 128.10, and Thunderbird 128.10
  * CVE-2025-4093 (bmo#1894100)
    Memory safety bug fixed in Firefox ESR 128.10 and Thunderbird
    128.10

OBS-URL: https://build.opensuse.org/request/show/1273775
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/MozillaThunderbird?expand=0&rev=360
2025-05-01 13:23:19 +00:00
Wolfgang Rosenauer
b9baeaa3a2 - Mozilla Thunderbird ESR 128.10.0
* Changed color override defaults with high contrast mode on
    macOS and Linux
  * Using Delete column in "Search Messages..." window could delete
    other messages
  MFSA 2025-32 (bsc#1241621)
  * CVE-2025-2817 (bmo#1917536)
    Privilege escalation in Thunderbird Updater
  * CVE-2025-4082 (bmo#1937097)
    WebGL shader attribute memory corruption in Thunderbird for
    macOS
  * CVE-2025-4083 (bmo#1958350)
    Process isolation bypass using "javascript:" URI links in
    cross-origin frames
  * CVE-2025-4084 (bmo#1949994, bmo#1956698, bmo#1960198)
    Potential local code execution in "copy as cURL" command
  * CVE-2025-4087 (bmo#1952465)
    Unsafe attribute access during XPath parsing
  * CVE-2025-4091 (bmo#1951161, bmo#1952105)
    Memory safety bugs fixed in Firefox 138, Thunderbird 138,
    Firefox ESR 128.10, and Thunderbird 128.10
  * CVE-2025-4093 (bmo#1894100)
    Memory safety bug fixed in Firefox ESR 128.10 and Thunderbird
    128.10

OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=812
2025-05-01 04:56:54 +00:00