Page MenuHomeSolus

Update Thunderbird to version 68.9.0
AbandonedPublic

Authored by rad4day on Jun 5 2020, 6:06 PM.
Tags
None
Referenced Files
F11053123: D8992.diff
Thu, Aug 10, 10:40 PM
F10926703: D8992.id.diff
Jul 10 2023, 2:07 PM
F10876077: D8992.id21658.diff
Jun 20 2023, 9:00 AM
F10870200: D8992.diff
Jun 18 2023, 8:41 AM
F10712934: D8992.id.diff
May 2 2023, 1:45 PM
Subscribers
None

Details

Reviewers
None
Group Reviewers
Triage Team
Summary

Security fixes:

  • CVE-2020-12399: Timing attack on DSA signatures in NSS library
  • CVE-2020-12405: Use-after-free in SharedWorkerService
  • CVE-2020-12406: JavaScript Type confusion with NativeTypes
  • CVE-2020-12410: Memory safety bugs fixed in Thunderbird 68.9.0
  • CVE-2020-12398: Security downgrade with IMAP STARTTLS leads to information leakage

Signed-off-by: Tobias Manske <tobias.manske@mailbox.org>

Upstream Summary: https://www.thunderbird.net/en-US/thunderbird/68.9.0/releasenotes/
Security fixes: https://www.mozilla.org/en-US/security/advisories/mfsa2020-22/

Test Plan
  • Works fine on the surface level. 68.9.0 is mainly a security update for some high level security vulnerabilities

Diff Detail

Repository
R3035 thunderbird
Branch
master
Lint
No Lint Coverage
Unit
No Test Coverage

Event Timeline

I wasn't aware, that the languagepack build process is not deterministic and therefore produces a different checksum each time it is recompiled. (Probably because of the file timestamps?)

Therefore the langpack-checksum is bogus, removing any value from this revision.