-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 02 Sep 2026 09:10:45 -0400
Source: thunderbird
Binary: thunderbird thunderbird-dbgsym
Architecture: amd64
Version: 1:140.15.0esr-1~deb13u1
Distribution: trixie-security
Urgency: medium
Maintainer: amd64 / i386 Build Daemon (x86-ubc-02) <buildd_amd64-x86-ubc-02@buildd.debian.org>
Changed-By: Christoph Goehre <chris@sigxcpu.org>
Description:
 thunderbird - mail/news client with RSS, chat and integrated spam filter suppor
Changes:
 thunderbird (1:140.15.0esr-1~deb13u1) trixie-security; urgency=medium
 .
   * [4095154] New upstream version 140.15.0esr
     Fixed CVE issues in upstream version 140.15 (MFSA 2026-87):
     CVE-2026-84639: Uninitialized memory in MIME parsing
     CVE-2026-84640: One byte overflow read in mail parser
     CVE-2026-84641: Information disclosure due to malicious IMAP server
                     response
     CVE-2026-75874: Sandbox escape in the Remote Settings Client component
     CVE-2026-16365: Privilege escalation in the DOM: Workers component
     CVE-2026-84119: Sandbox escape due to use-after-free in the DOM:
                     Navigation component
     CVE-2026-84120: Use-after-free in the Audio/Video component
     CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security
                     component
     CVE-2026-84122: Use-after-free in the Audio/Video component
     CVE-2026-84124: Use-after-free in the DOM: Core &amp; HTML component
     CVE-2026-16371: Privilege escalation in the DOM: Navigation component
     CVE-2026-84131: Privilege escalation due to invalid pointer in the
                     Graphics component
     CVE-2026-84143: Internally found bugs fixed in Thunderbird 155,
                     Thunderbird ESR 153.2 and Thunderbird ESR 140.15
     CVE-2026-84145: Internally found bugs fixed in Thunderbird 155,
                     Thunderbird ESR 153.2 and Thunderbird ESR 140.15
Checksums-Sha1:
 ccf04e9d76c2b1dfe1481171b07daef11c5d3f48 531390084 thunderbird-dbgsym_140.15.0esr-1~deb13u1_amd64.deb
 17c283e019138649ddb18e5e79b44879905a6078 21361 thunderbird_140.15.0esr-1~deb13u1_amd64-buildd.buildinfo
 413ad95cbb1a7d5de02ff81d3dd1697b04d5fd97 70200704 thunderbird_140.15.0esr-1~deb13u1_amd64.deb
Checksums-Sha256:
 0a675b5ce751228dc0dfe0c1730cc7abc5e56a39899f530f082a696a8320c463 531390084 thunderbird-dbgsym_140.15.0esr-1~deb13u1_amd64.deb
 bf58694ce90a1348fdd97345764397d93badcb8a3bed94664dff0a55e8e38a53 21361 thunderbird_140.15.0esr-1~deb13u1_amd64-buildd.buildinfo
 920dcb1c0ecd52208f1d4300eda1a12790bb59616d369f0ebeb4cb1159e20eea 70200704 thunderbird_140.15.0esr-1~deb13u1_amd64.deb
Files:
 398bc32c6445e2be86858c693d81015d 531390084 debug optional thunderbird-dbgsym_140.15.0esr-1~deb13u1_amd64.deb
 cea1f1dfd0c0cd665813f0f1a52d41d3 21361 mail optional thunderbird_140.15.0esr-1~deb13u1_amd64-buildd.buildinfo
 d55a6952075913c84d7abbc12840e540 70200704 mail optional thunderbird_140.15.0esr-1~deb13u1_amd64.deb

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEb5EwsJvHBEjqIJYIbheoBegwXLIFAmqYhbYACgkQbheoBegw
XLIC0RAAoDat0OdOGc9lUPmyAesOYouywfcBWHmeZDnkpKXryfsuLvo59B+EnScK
/a9SbPlbPH42Bf7Q95RJ7yv/g8N1TFI9XXvm3utTd+04OgdqnimQhElbTdQRA2ov
ExsNOS7qGxhkunDiPQyCfAWB4OxvEAm1g2N9vacvZMGtITFFHvuZdKpiZriWjim+
odV5Nu0tJz7G9ctgEXumrY07PvnZTdbrfzvKIRncVZkQRgY2QrBrpatfj9+UxWVc
SGj/P/Ysuy6/OpDq2oESrTPN7cIvjDS/MapEmk4JLpa85mAznK9xSJAdQvMqhWsX
Ry3Qwp8zPz4OtSJjlLxYIeWfpIs9S11Kg55bwYIyySxcNaxqxYIIVeOocMV5sKaG
+dI1BwnW2QLPQBt9yuedPeVE3KcuZvm3dnhsCEV3xSk9Q26yWkoAbcIbm8dOZ1wH
SvwasDZIzLjdDoHEwstDCMsPrfvZGcJ2B+jpS3iX26EQhnawtP09OIjELVBGRK/t
gOyIHJz2UPEu0GwqJN3lpzLgOzrndo6USEgNkLQiqhVn8G+Ytol6h0TUCpTC9tBy
TIZHpzadkgOfkomSG+DXYp2bIHqNwxZVD74USOQ3WqAiZvDMzNA3DT0gEFurW+bl
OhLWE9wLUjzirpgk+KhjQSFfilz/4tGWvguD5xyXEwVdQbQFVNk=
=e0IH
-----END PGP SIGNATURE-----
