-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 02 Sep 2026 09:10:45 -0400 Source: thunderbird Architecture: source Version: 1:140.15.0esr-1~deb13u1 Distribution: trixie-security Urgency: medium Maintainer: Carsten Schoenert Changed-By: Christoph Goehre Changes: thunderbird (1:140.15.0esr-1~deb13u1) trixie-security; urgency=medium . * [4095154] New upstream version 140.15.0esr Fixed CVE issues in upstream version 140.15 (MFSA 2026-87): CVE-2026-84639: Uninitialized memory in MIME parsing CVE-2026-84640: One byte overflow read in mail parser CVE-2026-84641: Information disclosure due to malicious IMAP server response CVE-2026-75874: Sandbox escape in the Remote Settings Client component CVE-2026-16365: Privilege escalation in the DOM: Workers component CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component CVE-2026-84120: Use-after-free in the Audio/Video component CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component CVE-2026-84122: Use-after-free in the Audio/Video component CVE-2026-84124: Use-after-free in the DOM: Core & HTML component CVE-2026-16371: Privilege escalation in the DOM: Navigation component CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component CVE-2026-84143: Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15 CVE-2026-84145: Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15 Checksums-Sha1: 43899f7147664075d98d0efb1408ad681b837bf4 8496 thunderbird_140.15.0esr-1~deb13u1.dsc d8429f80890d339a19b58f1e3c9eb62374ee79ff 12278824 thunderbird_140.15.0esr.orig-thunderbird-l10n.tar.xz 7d13956f6a120a38432ae78827ababbfb7631440 786619936 thunderbird_140.15.0esr.orig.tar.xz a3637b28978495138d8a47ca1797be1ff9abf9dc 572508 thunderbird_140.15.0esr-1~deb13u1.debian.tar.xz Checksums-Sha256: 98cc4b9274a9721dabfca3a1a79988ab38cbbce9bcd3bab86d4eaee74c655794 8496 thunderbird_140.15.0esr-1~deb13u1.dsc de8e669e0230a221c215648d1cc26318f8cc873fa8e28acb610588eb8f853d4a 12278824 thunderbird_140.15.0esr.orig-thunderbird-l10n.tar.xz 0c492070521a3783c82856382bd6fb56ef515b9e40c3885d4dbe08f2274fcaa2 786619936 thunderbird_140.15.0esr.orig.tar.xz 1b9770e791300798aaad29e4bb0025f618c873ab1304b9a0f80b61b3d4a5fe63 572508 thunderbird_140.15.0esr-1~deb13u1.debian.tar.xz Files: bc0b95134fdc1eac8ea1b08b7d2e8efb 8496 mail optional thunderbird_140.15.0esr-1~deb13u1.dsc c6ec44bc8b63f914cfb1ff75369e7285 12278824 mail optional thunderbird_140.15.0esr.orig-thunderbird-l10n.tar.xz 95f592cc66813b4bdf63791d288cde66 786619936 mail optional thunderbird_140.15.0esr.orig.tar.xz bc5c9337a033aa5dd7e41291d3fa7445 572508 mail optional thunderbird_140.15.0esr-1~deb13u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEi5SBnCVVcKN0tizNJuPIdadEIO8FAmqYQHUACgkQJuPIdadE IO+UkA/+IN4yeK12TS9nxRT5UsAj+UFf6kFyhF6PcV6sPeiX+cpJOiASqQnDywjs nmac0aQgXBrSIZHjSRmJvMIU9FgbBH2PVp2TzQRc64tu9uptm6W2VtrozE6OIVJX YE9+FvXXhITShTYUK9p5c+uTFBla90KnqGBa0tJRUOec+RCDH1kmguWdTlTaDkal foQbn/S49x1MmypQWhO+AYZmq9IvWeuNOSATNdLrpa4B8ttAahURbCRN8VVpxcWp vRqHRCYtrIBYR4al8wELb9MSQRUpWibB3jwGrhfjnk6TspxL9VjdEl+1v+RF9KRZ tnQY3Oo9y4mGwBQVwNuTybD1zzNov78h+OmbZ6cD5XlRZNoOVxEQeOGz77cRWdmH tS17Kgg2X2P2OrFU2nQOeHQqS3bV5cNXIXKg/F+z6s+xzTK0y5m+4AyOoec4EWnH pYuZOYFw475ltXL1uipf5SpDi3Oi9/fagLt7UcAhExrvmB5OXgsXXg3+7d45qoWe MXdaMHTTI6cr0gyzVxht1vnHiyfSFM4yQvxrq74tX/i4CabedDH609hYmZt3dXlt hoTnQlBXq4i484TY2+1W1kqsfKyeL8ofLs3OkZZ3XFiuXbYcWvGJo8tcy1PWFLSC omLpDHNxeYbngMw1T+GzayqDnpWNllHwW/avfk9wv3v4NZ8GewE= =guG3 -----END PGP SIGNATURE-----