diff --git a/MozillaThunderbird b/MozillaThunderbird index 0027b98..4fb117d 160000 --- a/MozillaThunderbird +++ b/MozillaThunderbird @@ -1 +1 @@ -Subproject commit 0027b9883899ad1a38857403902aa19dc12e5e30c8f6f25aa9e28fe8721038de +Subproject commit 4fb117d27dd8d08b98659042c21bc18086192c12f5a65b201808ea7db9c1de1e diff --git a/patchinfo.20260113100304813079.93181000773252/_patchinfo b/patchinfo.20260113100304813079.93181000773252/_patchinfo new file mode 100644 index 0000000..2acd546 --- /dev/null +++ b/patchinfo.20260113100304813079.93181000773252/_patchinfo @@ -0,0 +1,47 @@ + + firefox: JIT miscompilation in the JavaScript Engine: JIT component + firefox: Use-after-free in the WebRTC: Signaling component + firefox: Privilege escalation in the Netmonitor component + firefox: Privilege escalation in the DOM: Notifications component + firefox: Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component + VUL-0: MozillaFirefox / MozillaThunderbird: update to 146.0 and 140.6esr + firefox: JIT miscompilation in the JavaScript Engine: JIT component + firefox: JIT miscompilation in the JavaScript Engine: JIT component + firefox: Privilege escalation in the Netmonitor component + firefox: Same-origin policy bypass in the Request Handling component + firefox: Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146 + Yoshio_Sato + important + security + Security update for MozillaThunderbird + This update for MozillaThunderbird fixes the following issues: + +Changes in MozillaThunderbird: + +- Mozilla Thunderbird 140.6.0 ESR + MFSA 2025-96 (bsc#1254551) + * CVE-2025-14321 (bmo#1992760) + Use-after-free in the WebRTC: Signaling component + * CVE-2025-14322 (bmo#1996473) + Sandbox escape due to incorrect boundary conditions in the + Graphics: CanvasWebGL component + * CVE-2025-14323 (bmo#1996555) + Privilege escalation in the DOM: Notifications component + * CVE-2025-14324 (bmo#1996840) + JIT miscompilation in the JavaScript Engine: JIT component + * CVE-2025-14325 (bmo#1998050) + JIT miscompilation in the JavaScript Engine: JIT component + * CVE-2025-14328 (bmo#1996761) + Privilege escalation in the Netmonitor component + * CVE-2025-14329 (bmo#1997018) + Privilege escalation in the Netmonitor component + * CVE-2025-14330 (bmo#1997503) + JIT miscompilation in the JavaScript Engine: JIT component + * CVE-2025-14331 (bmo#2000218) + Same-origin policy bypass in the Request Handling component + * CVE-2025-14333 (bmo#1966501, bmo#1997639) + Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird + ESR 140.6, Firefox 146 and Thunderbird 146 + + MozillaThunderbird +