From 11aeb7fac9a300ec4a713254dc8b089440fdfd95f7612f87dfc5d1c60b84a03e Mon Sep 17 00:00:00 2001 From: Wolfgang Rosenauer Date: Sat, 1 Aug 2020 11:17:36 +0000 Subject: [PATCH 1/2] Accepting request 823875 from home:AndreasStieger:branches:mozilla:Factory Mozilla Thunderbird 68.11.0 - MFSA 2020-35 (bsc#1174538) OBS-URL: https://build.opensuse.org/request/show/823875 OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=541 --- MozillaThunderbird.changes | 18 ++++++++++++++++++ MozillaThunderbird.spec | 4 ++-- l10n-68.10.0.tar.xz => l10n-68.11.0.tar.xz | 0 tar_stamps | 8 ++++---- thunderbird-68.10.0.source.tar.xz | 3 --- thunderbird-68.10.0.source.tar.xz.asc | 16 ---------------- thunderbird-68.11.0.source.tar.xz | 3 +++ thunderbird-68.11.0.source.tar.xz.asc | 16 ++++++++++++++++ 8 files changed, 43 insertions(+), 25 deletions(-) rename l10n-68.10.0.tar.xz => l10n-68.11.0.tar.xz (100%) delete mode 100644 thunderbird-68.10.0.source.tar.xz delete mode 100644 thunderbird-68.10.0.source.tar.xz.asc create mode 100644 thunderbird-68.11.0.source.tar.xz create mode 100644 thunderbird-68.11.0.source.tar.xz.asc diff --git a/MozillaThunderbird.changes b/MozillaThunderbird.changes index d8ac04e..5651539 100644 --- a/MozillaThunderbird.changes +++ b/MozillaThunderbird.changes @@ -1,3 +1,21 @@ +------------------------------------------------------------------- +Sat Aug 1 09:54:53 UTC 2020 - Andreas Stieger + +- Mozilla Thunderbird 68.11.0 + * fixed: FileLink attachments included as a link and file when + added from a network drive via drag & drop (bmo#793118) + MFSA 2020-35 (bsc#1174538) + * CVE-2020-15652 (bmo#1634872) + Potential leak of redirect targets when loading scripts in a + worker + * CVE-2020-6514 (bmo#1642792) + WebRTC data channel leaks internal address to peer + * CVE-2020-6463 (bmo#1635293) + Use-after-free in ANGLE gl::Texture::onUnbindAsSamplerTexture + * CVE-2020-15659 (bmo#1550133, bmo#1633880, bmo#1646787, + bmo#1650811) + Memory safety bugs fixed in Thunderbird 68.11 + ------------------------------------------------------------------- Wed Jul 1 21:00:23 UTC 2020 - Andreas Stieger diff --git a/MozillaThunderbird.spec b/MozillaThunderbird.spec index 5557c80..a4f5fc7 100644 --- a/MozillaThunderbird.spec +++ b/MozillaThunderbird.spec @@ -26,8 +26,8 @@ # major 69 # mainver %major.99 %define major 68 -%define mainver %major.10.0 -%define orig_version 68.10.0 +%define mainver %major.11.0 +%define orig_version 68.11.0 %define orig_suffix %{nil} %define update_channel release %define source_prefix thunderbird-%{mainver} diff --git a/l10n-68.10.0.tar.xz b/l10n-68.11.0.tar.xz similarity index 100% rename from l10n-68.10.0.tar.xz rename to l10n-68.11.0.tar.xz diff --git a/tar_stamps b/tar_stamps index 9c3a663..b430a32 100644 --- a/tar_stamps +++ b/tar_stamps @@ -1,10 +1,10 @@ PRODUCT="thunderbird" CHANNEL="esr68" -VERSION="68.10.0" +VERSION="68.11.0" VERSION_SUFFIX="" -PREV_VERSION="68.9.0" +PREV_VERSION="68.10.0" PREV_VERSION_SUFFIX="" #SKIP_LOCALES="" # Uncomment to skip l10n and compare-locales-generation RELEASE_REPO="https://hg.mozilla.org/releases/comm-esr68" -RELEASE_TAG="6a7c26eb22bfe18295497c720a73e24b29b0604e" -RELEASE_TIMESTAMP="20200629235513" +RELEASE_TAG="a247645d951bcedb356a0d9f273e878a7d4d2180" +RELEASE_TIMESTAMP="20200721201500" diff --git a/thunderbird-68.10.0.source.tar.xz b/thunderbird-68.10.0.source.tar.xz deleted file mode 100644 index ea32e53..0000000 --- a/thunderbird-68.10.0.source.tar.xz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:700ca2e21fef8f76134fc18d901fe890180c21a988ab39ad651554a8ed08a01d -size 331265676 diff --git a/thunderbird-68.10.0.source.tar.xz.asc b/thunderbird-68.10.0.source.tar.xz.asc deleted file mode 100644 index 70d6751..0000000 --- a/thunderbird-68.10.0.source.tar.xz.asc +++ /dev/null @@ -1,16 +0,0 @@ ------BEGIN PGP SIGNATURE----- - -iQIzBAABCgAdFiEECXsxMHeuYqAvhNpN8aZmj7t9Vy4FAl76uE0ACgkQ8aZmj7t9 -Vy42nhAAqeFrMSXjooB6Uh01KqvhL9n9l30NUElMX3icrZiZbbG8SbfJ+poSr5s3 -Ii9MMKi/+1uBJnSCqB/YOJbn1VPc/291bhoAGefzZHGKB1TLO6rdaNHB1lLrb6qH -UDwbjIrvOQat4CBG18j3XxP9g2JbT8JtgoBo8v7IaAcIyzjlo7jF+ToIWcjFJUI9 -Qij8GF0VQXTldv0mxU3m0Bol7nUOQfuOVHi0x8hPm2jQ2X3MOEVO8coKVovzUTJ5 -h7JE4hwkv5b8zqRmiLGLtu8Ju2Xwkwbh38MJ24kyjLS9Z6jsXdN1LDSDbZ4laVby -ug0WFWiZfnOwxSx/xTwCl8dQD1PBK4kr4bVl5pxZRSZFfhF/JS83xkTPBwWCzX2E -ePe9ehQ0bcsTGrMlMd2CecU+a+M+wgDL7arOOhgy3Yu+CLRgx7KhBWef5mC3/uvw -5Np4T3//0YvpxrXO7bD/+z7+vByChSTLAvT1X4tvj0/rqe7I5HEH4hjcDWBfwG1S -V3MIWY8heMmY2/kOwte20VUyUMfuDBjvXnzuvWzFVCce0Hg2kdxx2nAYO4o03yos -LAiMy48bmRTR0/ePdnINxHj5fPzWC/oeL5l/2u5F/XT0wrOqFnqhNEYw/K+7U8N5 -Ihj4kRfboAlI4v8AHaFAyDqm5Ypms8xhFB24kkOsB8fyO8TN60s= -=1kyN ------END PGP SIGNATURE----- diff --git a/thunderbird-68.11.0.source.tar.xz b/thunderbird-68.11.0.source.tar.xz new file mode 100644 index 0000000..545d3a4 --- /dev/null +++ b/thunderbird-68.11.0.source.tar.xz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:0d2f403c7aca55ab130b7262ff8afc0254e5c0471db01f1631976df68a6af5f2 +size 337797560 diff --git a/thunderbird-68.11.0.source.tar.xz.asc b/thunderbird-68.11.0.source.tar.xz.asc new file mode 100644 index 0000000..8d03dd5 --- /dev/null +++ b/thunderbird-68.11.0.source.tar.xz.asc @@ -0,0 +1,16 @@ +-----BEGIN PGP SIGNATURE----- + +iQIzBAABCgAdFiEECXsxMHeuYqAvhNpN8aZmj7t9Vy4FAl8Ylw4ACgkQ8aZmj7t9 +Vy6kNw//QPPzP/G0VpLOVPe7gz+K82CGzqe+cN3TCIJ88LlTNIMfnGztQi6PIhFk +uofGz4lWz7xkV6r8rinlktoaB+IXFM3biemhAYDu813TKLVdssKLC7rA4/kbWxEH +6dsEoSlH9+FZWtf4Ip4y6mX+Lm7fSXittJ2AD4J85nmoRnJ7GvQVESJzDTMQ0ZSS +Jju0Zh9QtCB84WhaFneLh7nTqwjmhDBPg2GmiG6OViMg36LtNXiekOm8xJE+qhca +crPeH/LGyqscZ9o6h+HY27CN7Oi3HElCMj9/5L5G8k8o/Yzv16K/bdvwJP9Ewdvk +laJ3FRcOGP9uglZWPlXVfjpP/T1Bbl5eElgddU/TqALt+9x2P66qf4UTv4SewcnX +M7ME/FBNYJOamE8NdSsTata0nxlH3VTzn0dGcxU0h0/bHr1+cV1raZZhOqVcdABd +I3O5djrrwYCGvWDfSAC6W1DpL+VEqY1NIKK6PRrFrl4I7qTmspy654QfoaS8dWOB +dLIyKR8tLCYDlO09koRUTo9vdT3Ig1Ggl/7WfklnA60sNByaUBdQmTc84uoGeVst +P5P49cQunInAPHzOiVyGziB36Vya/j22ETaK860t0yn+NYXxVZWdp5Ckeu9QEAJ6 +bVdIA4YAVZt7jhV62oX6fRQa51mGpsPXhDOuCnPGGIhDprn7Pok= +=BZp0 +-----END PGP SIGNATURE----- From 17467a5a91cb2abb1ea08e435e353885e5219125ee1db3467f763dd962512602 Mon Sep 17 00:00:00 2001 From: Wolfgang Rosenauer Date: Sat, 1 Aug 2020 11:37:02 +0000 Subject: [PATCH 2/2] Accepting request 823877 from home:AndreasStieger:branches:mozilla:Factory some past changelog OBS-URL: https://build.opensuse.org/request/show/823877 OBS-URL: https://build.opensuse.org/package/show/mozilla:Factory/MozillaThunderbird?expand=0&rev=542 --- MozillaThunderbird.changes | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/MozillaThunderbird.changes b/MozillaThunderbird.changes index 5651539..b6bfb12 100644 --- a/MozillaThunderbird.changes +++ b/MozillaThunderbird.changes @@ -24,6 +24,22 @@ Wed Jul 1 21:00:23 UTC 2020 - Andreas Stieger (bmo#1644024) * fixed: Calendar: Filtering tasks did not work when "Incomplete Tasks" was selected (bmo#1593711) + MFSA 2020-26 (bsc#1173576) + * CVE-2020-12417 (bmo#1640737) + Memory corruption due to missing sign-extension for ValueTags + on ARM64 + * CVE-2020-12418 (bmo#1641303) + Information disclosure due to manipulated URL object + * CVE-2020-12419 (bmo#1643874) + Use-after-free in nsGlobalWindowInner + * CVE-2020-12420 (bmo#1643437) + Use-After-Free when trying to connect to a STUN server + * MFSA-2020-0001 (bmo#1606610) + Automatic account setup leaks Microsoft Exchange login + credentials + * CVE-2020-12421 (bmo#1308251) + Add-On updates did not respect the same certificate trust + rules as software updates ------------------------------------------------------------------- Thu Jun 11 14:52:51 UTC 2020 - Wolfgang Rosenauer