Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

MozillaThunderbird-140.13.0-1.2 RPM for x86_64

From OpenSuSE Tumbleweed for x86_64

Name: MozillaThunderbird Distribution: openSUSE Tumbleweed
Version: 140.13.0 Vendor: openSUSE
Release: 1.2 Build date: Tue Jul 21 15:42:04 2026
Group: Productivity/Networking/Email/Clients Build host: reproducible
Size: 305248193 Source RPM: MozillaThunderbird-140.13.0-1.2.src.rpm
Packager: https://bugs.opensuse.org
Url: https://www.thunderbird.net/
Summary: An integrated email, news feeds, chat, and newsgroups client
Thunderbird is a free, open-source, cross-platform application for
managing email, news feeds, chat, and news groups. It is a local
(rather than browser- or web-based) email application that is powerful
yet easy to use.

Provides

Requires

License

MPL-2.0

Changelog

* Tue Jul 21 2026 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 140.13.0 ESR
    MFSA 2026-72 (bsc#1271649)
    * CVE-2026-14899 (bmo#2046137)
      Off-by-one out of bounds read in MIME header parser for forwarding
    * CVE-2026-15718 (bmo#2045443)
      Invalid pointer in the JavaScript: WebAssembly component
    * CVE-2026-15719 (bmo#2043820)
      Site isolation issue in the DOM: Navigation component
    * CVE-2026-16349 (bmo#2034682)
      Same-origin policy bypass in the DOM: Navigation component
    * CVE-2026-16350 (bmo#2042033)
      Incorrect boundary conditions in the Audio/Video: cubeb component
    * CVE-2026-16362 (bmo#2043188)
      Use-after-free in the WebRTC: Audio/Video component
    * CVE-2026-16351 (bmo#2045468)
      Sandbox escape due to use-after-free in the DOM: Navigation component
    * CVE-2026-16352 (bmo#2046416)
      Sandbox escape due to use-after-free in the Disability Access
      APIs component
    * CVE-2026-16363 (bmo#2047689)
      JIT miscompilation in the JavaScript: WebAssembly component
    * CVE-2026-16353 (bmo#2049523)
      Invalid pointer in the DOM: Bindings (WebIDL) component
    * CVE-2026-16354 (bmo#2050626)
      Information disclosure in the Graphics: ImageLib component
    * CVE-2026-16368 (bmo#2051015)
      Incorrect boundary conditions in the JavaScript: WebAssembly component
    * CVE-2026-16369 (bmo#2051854)
      Integer overflow in the JavaScript: WebAssembly component
    * CVE-2026-16355 (bmo#2052207)
      JIT miscompilation in the JavaScript Engine: JIT component
    * CVE-2026-16356 (bmo#2052562)
      Sandbox escape due to use-after-free in the Disability Access
      APIs component
    * CVE-2026-16357 (bmo#2053326)
      Incorrect boundary conditions in the Graphics component
    * CVE-2026-16371 (bmo#2008369)
      Privilege escalation in the DOM: Navigation component
    * CVE-2026-16374 (bmo#2027519)
      Information disclosure in the Framework component in DevTools
    * CVE-2026-16375 (bmo#2032140)
      Site isolation issue in the Networking: HTTP component
    * CVE-2026-16377 (bmo#2037770)
      Mitigation bypass in the PDF Viewer component
    * CVE-2026-16379 (bmo#2039452)
      Privilege escalation in the DOM: Content Processes component
    * CVE-2026-16358 (bmo#2040119)
      Site isolation issue in the Graphics: WebRender component
    * CVE-2026-16381 (bmo#2041001)
      Same-origin policy bypass in the Networking: DNS component
    * CVE-2026-16383 (bmo#2041902)
      Mitigation bypass in the DOM: Networking component
    * CVE-2026-16387 (bmo#2043200)
      Site isolation issue in the Networking component
    * CVE-2026-16390 (bmo#2044527)
      Mitigation bypass in the Enterprise Policies component
    * CVE-2026-16391 (bmo#2044536)
      Information disclosure in the Storage: IndexedDB component
    * CVE-2026-16359 (bmo#2045424)
      Incorrect boundary conditions in the Audio/Video: GMP component
    * CVE-2026-16396 (bmo#2047240)
      Privilege escalation in WebExtensions
    * CVE-2026-16405 (bmo#2036591)
      Information disclosure in the Networking: WebSockets component
    * CVE-2026-16412 (bmo#2005113, bmo#2025369, bmo#2026301, bmo#2028663,
      bmo#2029761, bmo#2042242, bmo#2043035, bmo#2043271, bmo#2043300,
      bmo#2044612, bmo#2045057, bmo#2045187, bmo#2045378, bmo#2045402,
      bmo#2045406, bmo#2045407, bmo#2045413, bmo#2045417, bmo#2045482,
      bmo#2045611, bmo#2045616, bmo#2045618, bmo#2045626, bmo#2045730,
      bmo#2045732, bmo#2045756, bmo#2045769, bmo#2045771, bmo#2046917,
      bmo#2047718, bmo#2047957, bmo#2048934, bmo#2049818, bmo#2049822,
      bmo#2050151, bmo#2050368, bmo#2051653, bmo#2051658, bmo#2053635,
      bmo#2053637)
      Memory safety bugs fixed in Thunderbird ESR 140.13 and
      Thunderbird 153
    * CVE-2026-16360 (bmo#2022635, bmo#2028004, bmo#2035756, bmo#2043739,
      bmo#2045184, bmo#2045185, bmo#2045198, bmo#2045281, bmo#2045392,
      bmo#2045395, bmo#2045396, bmo#2045397, bmo#2045405, bmo#2045414,
      bmo#2045415, bmo#2045451, bmo#2045454, bmo#2045508, bmo#2045510,
      bmo#2045513, bmo#2045515, bmo#2045518, bmo#2045604, bmo#2045607,
      bmo#2045612, bmo#2045614, bmo#2045617, bmo#2045619, bmo#2045624,
      bmo#2045625, bmo#2045729, bmo#2045737, bmo#2045741, bmo#2045742,
      bmo#2045744, bmo#2045763, bmo#2045767, bmo#2045770, bmo#2045772,
      bmo#2045773, bmo#2045775, bmo#2045783, bmo#2045833, bmo#2045848,
      bmo#2045865, bmo#2045875, bmo#2045957, bmo#2047719, bmo#2047723,
      bmo#2047729, bmo#2048795, bmo#2048799, bmo#2048801, bmo#2049392,
      bmo#2049397, bmo#2049398, bmo#2049399, bmo#2049404, bmo#2049405,
      bmo#2049407, bmo#2049805, bmo#2049812, bmo#2050657, bmo#2050668,
      bmo#2050990, bmo#2051666, bmo#2053166, bmo#2053273, bmo#2053576,
      bmo#2053583, bmo#2053587)
      Memory safety bugs fixed in Thunderbird ESR 140.13 and
      Thunderbird 153
    * CVE-2026-16361 (bmo#2029734, bmo#2036518)
      Memory safety bugs fixed in Thunderbird ESR 140.13
  - require transitional rust-cbindgen-0_29_<F2> package to build
* Wed Jul 01 2026 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 140.12.1 ESR
    MFSA 2026-63
    * CVE-2026-57962 (bmo#2042872)
      Denial-of-service via malicious LDAP address-book server
    * CVE-2026-57963 (bmo#2042910)
      Chat UI manipulation by injection
* Wed Jun 17 2026 Manfred Hollstein <manfred.h@gmx.net>
  - Enable clang_build to allow building with the latest versions of
    llvm/clang due to them dropping support for update-alternatives.
* Sat Jun 13 2026 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 140.12.0 ESR
    MFSA 2026-61 (bsc#1268071)
    * CVE-2026-12289 (bmo#2023443)
      Privilege escalation in the Graphics: WebRender component
    * CVE-2026-12290 (bmo#2024852)
      Memory safety bug fixed in Thunderbird ESR 140.12
    * CVE-2026-12291 (bmo#2036929)
      Use-after-free in the Networking: HTTP component
    * CVE-2026-12292 (bmo#2038465)
      Incorrect boundary conditions in the Web Audio component
    * CVE-2026-12294 (bmo#2039873)
      Sandbox escape in the DOM: Workers component
    * CVE-2026-12295 (bmo#2040160)
      Sandbox escape in the DOM: Navigation component
    * CVE-2026-12298 (bmo#2041981)
      Memory safety bug fixed in Thunderbird ESR 140.12
    * CVE-2026-12296 (bmo#2040515)
      Sandbox escape in the Security: Process Sandboxing component
    * CVE-2026-12297 (bmo#2041610)
      Sandbox escape due to incorrect boundary conditions in the
      Networking component
    * CVE-2026-12299 (bmo#2043139)
      JIT miscompilation in the DOM: Core & HTML component
    * CVE-2026-12329 (bmo#2044738)
      Memory safety bug fixed in Thunderbird ESR 140.12
    * CVE-2026-12302 (bmo#2034489)
      Mitigation bypass in the DOM: Security component
    * CVE-2026-12304 (bmo#2034944)
      Same-origin policy bypass in the Networking: Cookies component
    * CVE-2026-12305 (bmo#2037290)
      Memory safety bug fixed in Thunderbird ESR 140.12
    * CVE-2026-12306 (bmo#2037323)
      Memory safety bug fixed in Thunderbird ESR 140.12
    * CVE-2026-12307 (bmo#2038133)
      Memory safety bug fixed in Thunderbird ESR 140.12
    * CVE-2026-12308 (bmo#2038302)
      Memory safety bug fixed in Thunderbird ESR 140.12
    * CVE-2026-12309 (bmo#2038476)
      Memory safety bug fixed in Thunderbird ESR 140.12
    * CVE-2026-12310 (bmo#2039707)
      Memory safety bug fixed in Thunderbird ESR 140.12
    * CVE-2026-12311 (bmo#2040177)
      Information disclosure, sandbox escape in the Security:
      Process Sandboxing component
    * CVE-2026-12312 (bmo#2040383)
      Memory safety bug fixed in Thunderbird ESR 140.12
    * CVE-2026-12313 (bmo#2040477)
      Information disclosure, sandbox escape in the Security:
      Process Sandboxing component
    * CVE-2026-12314 (bmo#2041856)
      Memory safety bug fixed in Thunderbird ESR 140.12
    * CVE-2026-12315 (bmo#2042058)
      Mitigation bypass in the DOM: Security component
    * CVE-2026-12330 (bmo#2029326)
      Incorrect boundary conditions in the Internationalization
      component
    * CVE-2026-12324 (bmo#2038444)
      Incorrect boundary conditions in the Graphics: CanvasWebGL
      component
    * CVE-2026-12325 (bmo#2039443)
      Denial-of-service in the Graphics: ImageLib component
    * CVE-2026-12327 (bmo#2011842, bmo#2023902, bmo#2025512, bmo#2027312,
      bmo#2029444, bmo#2036571, bmo#2036900, bmo#2036936, bmo#2037995,
      bmo#2038551, bmo#2040717, bmo#2042724)
      Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird
      ESR 140.12, Firefox 152 and Thunderbird 152
    * CVE-2026-12328 (bmo#2029402, bmo#2038477, bmo#2039726, bmo#2041373,
      bmo#2042268, bmo#2042451, bmo#2042782, bmo#2042858, bmo#2042929,
      bmo#2042965, bmo#2043213)
      Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR
      140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152
* Tue May 26 2026 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 140.11.1 ESR
    * There are no Thunderbird changes requiring release notes in
      this release
* Sat May 23 2026 Manfred Hollstein <manfred.h@gmx.net>
  - Refresh thunderbird-glibc-2.43.patch and re-enable its application
    on systems with glibc >= 2.43
* Tue May 19 2026 Max Lin <mlin@suse.com>
  - Use BuildRequires: libclang13 to instead of llvm21-libclang13 on
    Leap 16.1
    * Built llvm21 coming from SLFO does not name a llvm versioned
      libclang13
* Sat May 16 2026 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 140.11.0 ESR
    MFSA 2026-51 (bsc#1265212)
    * CVE-2026-8946 (bmo#2029070)
      Incorrect boundary conditions in the Audio/Video: Web Codecs
      component
    * CVE-2026-8388 (bmo#2036978)
      Incorrect boundary conditions in the JavaScript Engine: JIT
      component
    * CVE-2026-8947 (bmo#2038439)
      Use-after-free in the DOM: Bindings (WebIDL) component
    * CVE-2026-8391 (bmo#2038575)
      Other issue in the JavaScript Engine component
    * CVE-2026-8401 (bmo#2038679)
      Sandbox escape in the Profile Backup component
    * CVE-2026-8949 (bmo#1355639)
      Integer overflow in the Widget: Win32 component
    * CVE-2026-8950 (bmo#1965430)
      Same-origin policy bypass in the Networking: HTTP component
    * CVE-2026-8953 (bmo#2029511)
      Sandbox escape due to use-after-free in the Disability Access
      APIs component
    * CVE-2026-8954 (bmo#2030747)
      Incorrect boundary conditions, integer overflow in the
      Audio/Video component
    * CVE-2026-8955 (bmo#2031064)
      Privilege escalation in the DOM: Workers component
    * CVE-2026-8956 (bmo#2032427)
      Integer overflow in the Networking: JAR component
    * CVE-2026-8957 (bmo#2033850)
      Privilege escalation in the Enterprise Policies component
    * CVE-2026-8958 (bmo#2034713)
      Information disclosure, sandbox escape in the Security:
      Process Sandboxing component
    * CVE-2026-8959 (bmo#2034754)
      Sandbox escape due to incorrect boundary conditions in the
      Widget: Win32 component
    * CVE-2026-8961 (bmo#1962625)
      Spoofing issue in the Form Autofill component
    * CVE-2026-8962 (bmo#2004804)
      Mitigation bypass in the DOM: Security component
    * CVE-2026-8968 (bmo#2030467)
      Denial-of-service due to invalid pointer in the Audio/Video:
      Web Codecs component
    * CVE-2026-8970 (bmo#2032174)
      Privilege escalation in the Security component
    * CVE-2026-8974 (bmo#1784128, bmo#1883230, bmo#1983677, bmo#2022390,
      bmo#2023116, bmo#2023657, bmo#2024255, bmo#2024418, bmo#2024441,
      bmo#2024447, bmo#2024966, bmo#2025412, bmo#2025467, bmo#2025940,
      bmo#2025950, bmo#2025956, bmo#2026284, bmo#2027247, bmo#2027255,
      bmo#2027288, bmo#2027306, bmo#2027322, bmo#2027332, bmo#2027333,
      bmo#2028266, bmo#2028292, bmo#2028319, bmo#2028526, bmo#2028870,
      bmo#2028876, bmo#2028882, bmo#2029062, bmo#2029309, bmo#2029414,
      bmo#2029422, bmo#2029428, bmo#2029447, bmo#2029732, bmo#2029785,
      bmo#2029793, bmo#2029813, bmo#2029899, bmo#2031028, bmo#2031457,
      bmo#2032039, bmo#2033610, bmo#2033854, bmo#2034498, bmo#2034628,
      bmo#2034978, bmo#2035966, bmo#2036668, bmo#2036905, bmo#2036930)
      Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird 151
    * CVE-2026-8975 (bmo#1860195, bmo#2029325, bmo#2029429, bmo#2029910,
      bmo#2035915, bmo#2038669, bmo#2038678)
      Memory safety bugs fixed in Thunderbird 140.11 and Thunderbird 151
  - removed obsolete patches
    * thunderbird-bmo2006630.patch
    * mozilla-bmo2031958.patch
* Fri May 08 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Thunderbird 140.10.2
    MFSA 2026-44 (bsc#1264378)
    * CVE-2026-8090 (bmo#2034352)
      Use-after-free in the DOM: Networking component
    * CVE-2026-8094 (bmo#2035939)
      Other issue in the WebRTC component
    * CVE-2026-8092 (bmo#1806249, bmo#2021977, bmo#2022576, bmo#2022722,
      bmo#2024439, bmo#2027883, bmo#2029463, bmo#2030323, bmo#2032042,
      bmo#2032043, bmo#2033270, bmo#2033637, bmo#2034422, bmo#2034496,
      bmo#2035879, bmo#2036516)
      Memory safety bugs fixed in Thunderbird ESR 140.10.2 and
      Thunderbird 150.0.2
* Tue May 05 2026 Stanislav Brabec <sbrabec@suse.com>
  - Migrate from deprecated %suse_update_desktop_file to
    %translate_suse_desktop. (boo#1158957)
* Tue May 05 2026 Manfred Hollstein <manfred.h@gmx.net>
  - Add thunderbird-glibc-2.43.patch as source22 and apply it only
    if glibc newer than 2.42 is installed in the build environment.
    It serves to remove conflicting definitions and adapt the syscall
    in accordance with glibc-2.43.
* Wed Apr 29 2026 Manfred Hollstein <manfred.h@gmx.net>
  - Further tests have shown that the rule which llvm version should
    be used, can be simplified: only on TW, Slowroll and Factory we
    need to explicitly BuildRequire the llvm21 based packages, while
    on all other (i.e. Leap) distribution versions we can stick with
    the distro's default release of llvm.
* Wed Apr 29 2026 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 140.10.1 ESR
    MFSA 2026-39 (bsc#1263110)
    * CVE-2026-7320 (bmo#2027433)
      Information disclosure due to incorrect boundary conditions
      in the Audio/Video component
    * CVE-2026-7321 (bmo#2029461)
      Sandbox escape due to incorrect boundary conditions in the
      WebRTC: Networking component
    * CVE-2026-7322 (bmo#2021904, bmo#2022731, bmo#2027158,
      bmo#2027733, bmo#2027973, bmo#2027976, bmo#2028231,
      bmo#2028731, bmo#2028886, bmo#2029067, bmo#2029700,
      bmo#2029724, bmo#2029806, bmo#2029814, bmo#2030108,
      bmo#2030111, bmo#2031524, bmo#2031921, bmo#2032040)
      Memory safety bugs fixed in Thunderbird ESR 140.10.1 and
      Thunderbird 150.0.1
    * CVE-2026-7323 (bmo#2028537, bmo#2029911, bmo#2031121,
      bmo#2033602)
      Memory safety bugs fixed in Thunderbird ESR 140.10.1 and
      Thunderbird 150.0.1
  - added mozilla-bmo2031958.patch to fix incompatible pointer types
    (bmo#2031958)
* Wed Apr 29 2026 Manfred Hollstein <manfred.h@gmx.net>
  - Explicitly BuildIgnore: clang-tools to avoid pulling in the remaining
    llvm22 packages. Also add BuildRequire for libclang13 provided by
    the llvm version we use.
  - LLVM22 breaks building firefox-esr and MozillaThunderbird, restrict
    clang-devel to clang21-devel on TW, Slowroll and Factory.
    Use clang19-devel on all older distributions.
* Fri Apr 24 2026 Max Lin <mlin@suse.com>
  - Fix suse_version check since SLE 16 SP1 will use a value of 1610
* Tue Apr 21 2026 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 140.10.0 ESR
    * Newly translated strings were not available in Thunderbird
    MFSA 2026-34 (bsc#1262230)
    * CVE-2026-6746 (bmo#2014596)
      Use-after-free in the DOM: Core & HTML component
    * CVE-2026-6747 (bmo#2021769)
      Use-after-free in the WebRTC component
    * CVE-2026-6748 (bmo#2022604)
      Uninitialized memory in the Audio/Video: Web Codecs component
    * CVE-2026-6749 (bmo#2022610)
      Information disclosure due to uninitialized memory in the
      Graphics: Canvas2D component
    * CVE-2026-6750 (bmo#2023407)
      Privilege escalation in the Graphics: WebRender component
    * CVE-2026-6751 (bmo#2025883)
      Uninitialized memory in the Audio/Video: Web Codecs component
    * CVE-2026-6752 (bmo#2027499)
      Incorrect boundary conditions in the WebRTC component
    * CVE-2026-6753 (bmo#2027501)
      Incorrect boundary conditions in the WebRTC component
    * CVE-2026-6754 (bmo#2027541)
      Use-after-free in the JavaScript Engine component
    * CVE-2026-6757 (bmo#2013588)
      Invalid pointer in the JavaScript: WebAssembly component
    * CVE-2026-6759 (bmo#2016164)
      Use-after-free in the Widget: Cocoa component
    * CVE-2026-6761 (bmo#2017857)
      Privilege escalation in the Networking component
    * CVE-2026-6762 (bmo#2021080)
      Spoofing issue in the DOM: Core & HTML component
    * CVE-2026-6763 (bmo#2021666)
      Mitigation bypass in the File Handling component
    * CVE-2026-6764 (bmo#2022162)
      Incorrect boundary conditions in the DOM: Device Interfaces
      component
    * CVE-2026-6765 (bmo#2022419)
      Information disclosure in the Form Autofill component
    * CVE-2026-6766 (bmo#2023207)
      Incorrect boundary conditions in the Libraries component in NSS
    * CVE-2026-6767 (bmo#2023209)
      Other issue in the Libraries component in NSS
    * CVE-2026-6769 (bmo#2023753)
      Privilege escalation in the Debugger component
    * CVE-2026-6770 (bmo#2024220)
      Other issue in the Storage: IndexedDB component
    * CVE-2026-6771 (bmo#2025067)
      Mitigation bypass in the DOM: Security component
    * CVE-2026-6772 (bmo#2026089)
      Incorrect boundary conditions in the Libraries component in NSS
    * CVE-2026-6776 (bmo#2021770)
      Incorrect boundary conditions in the WebRTC: Networking
      component
    * CVE-2026-6785 (bmo#1935995, bmo#1999158, bmo#2015952, bmo#2021909,
      bmo#2022026, bmo#2022041, bmo#2022088, bmo#2022276, bmo#2022335,
      bmo#2022338, bmo#2022373, bmo#2022597, bmo#2022874, bmo#2023276,
      bmo#2023544, bmo#2023551, bmo#2023599, bmo#2023608, bmo#2023814,
      bmo#2024233, bmo#2024239, bmo#2024241, bmo#2024242, bmo#2024250,
      bmo#2024251, bmo#2024343, bmo#2024422, bmo#2024425, bmo#2024440,
      bmo#2024442, bmo#2024446, bmo#2024458, bmo#2024463, bmo#2024478,
      bmo#2024650, bmo#2024653, bmo#2024654, bmo#2024655, bmo#2024656,
      bmo#2024661, bmo#2024662, bmo#2024668, bmo#2024919, bmo#2025278,
      bmo#2025349, bmo#2025350, bmo#2025354, bmo#2025360, bmo#2025363,
      bmo#2025370, bmo#2025379, bmo#2025381, bmo#2025399, bmo#2025400,
      bmo#2025403, bmo#2025407, bmo#2025415, bmo#2025420, bmo#2025427,
      bmo#2025429, bmo#2025430, bmo#2025479, bmo#2025489, bmo#2025493,
      bmo#2025497, bmo#2025502, bmo#2025515, bmo#2025517, bmo#2025526,
      bmo#2025609, bmo#2025948, bmo#2025949, bmo#2025951, bmo#2025953,
      bmo#2025955, bmo#2025962, bmo#2025969, bmo#2025970, bmo#2025971,
      bmo#2025973, bmo#2025976, bmo#2025977, bmo#2026280, bmo#2026285,
      bmo#2026293, bmo#2026296, bmo#2026310, bmo#2027237, bmo#2027260,
      bmo#2027268, bmo#2027277, bmo#2027284, bmo#2027291, bmo#2027293,
      bmo#2027298, bmo#2027330, bmo#2027342, bmo#2027345, bmo#2027359,
      bmo#2027365, bmo#2027378, bmo#2027754, bmo#2027959, bmo#2027962,
      bmo#2027964, bmo#2027971, bmo#2027974, bmo#2027979, bmo#2027982,
      bmo#2027995, bmo#2028001, bmo#2028267, bmo#2028268, bmo#2028275,
      bmo#2028288, bmo#2028290, bmo#2028291, bmo#2028528, bmo#2028551,
      bmo#2028627, bmo#2028879, bmo#2028889, bmo#2029061, bmo#2029071,
      bmo#2029283, bmo#2029296, bmo#2029314, bmo#2029323, bmo#2029411,
      bmo#2029423, bmo#2029424, bmo#2029425, bmo#2029427, bmo#2029436,
      bmo#2029440, bmo#2029449, bmo#2029450, bmo#2029458, bmo#2029462,
      bmo#2029468, bmo#2029472, bmo#2029690, bmo#2029707, bmo#2029708,
      bmo#2029728, bmo#2029802, bmo#2029896, bmo#2029906, bmo#2030106,
      bmo#2030118, bmo#2030123, bmo#2030135, bmo#2030230, bmo#2030320)
      Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR
      140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150
    * CVE-2026-6786 (bmo#2010727, bmo#2019004, bmo#2019224, bmo#2019547,
      bmo#2020378, bmo#2022381, bmo#2022608, bmo#2022785, bmo#2023120,
      bmo#2023128, bmo#2023140, bmo#2023279, bmo#2023836, bmo#2023882,
      bmo#2023925, bmo#2023950, bmo#2023959, bmo#2023965, bmo#2024243,
      bmo#2024245, bmo#2024247, bmo#2024253, bmo#2024346, bmo#2024357,
      bmo#2024416, bmo#2024420, bmo#2024429, bmo#2024432, bmo#2024455,
      bmo#2024466, bmo#2024468, bmo#2024476, bmo#2024664, bmo#2024666,
      bmo#2024669, bmo#2024670, bmo#2024671, bmo#2024761, bmo#2024918,
      bmo#2025292, bmo#2025332, bmo#2025348, bmo#2025384, bmo#2025395,
      bmo#2025458, bmo#2025461, bmo#2025463, bmo#2025481, bmo#2025483,
      bmo#2025485, bmo#2025494, bmo#2025506, bmo#2025511, bmo#2025513,
      bmo#2025520, bmo#2026277, bmo#2026282, bmo#2026288, bmo#2026289,
      bmo#2026311, bmo#2026312, bmo#2026869, bmo#2027152, bmo#2027161,
      bmo#2027238, bmo#2027261, bmo#2027269, bmo#2027274, bmo#2027280,
      bmo#2027281, bmo#2027300, bmo#2027302, bmo#2027331, bmo#2027339,
      bmo#2027340, bmo#2027738, bmo#2027975, bmo#2028000, bmo#2028011,
      bmo#2028289, bmo#2028525, bmo#2028728, bmo#2028887, bmo#2028888,
      bmo#2028896, bmo#2029063, bmo#2029064, bmo#2029290, bmo#2029291,
      bmo#2029294, bmo#2029300, bmo#2029304, bmo#2029316, bmo#2029317,
      bmo#2029401, bmo#2029415, bmo#2029430, bmo#2029457, bmo#2029727,
      bmo#2029735, bmo#2029743, bmo#2029752, bmo#2029754, bmo#2029776,
      bmo#2029809, bmo#2030324, bmo#2030370)
      Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird
      ESR 140.10, Firefox 150 and Thunderbird 150
* Sun Apr 05 2026 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 140.9.1 ESR
    MFSA 2026-29
    * CVE-2026-5732 (bmo#2017867)
      Incorrect boundary conditions, integer overflow in the
      Graphics: Text component
    * CVE-2026-5731 (bmo#2021894, bmo#2022225, bmo#2022252, bmo#2022294,
      bmo#2023007, bmo#2023130, bmo#2023191, bmo#2023364, bmo#2023829,
      bmo#2024074, bmo#2024417, bmo#2024433, bmo#2024436, bmo#2024437,
      bmo#2024453, bmo#2024461, bmo#2024462, bmo#2024472, bmo#2024474,
      bmo#2024477, bmo#2025364, bmo#2025401, bmo#2025402, bmo#2025472,
      bmo#2026287, bmo#2026299, bmo#2026305, bmo#2026426)
      Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR
      140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and
      Thunderbird 149.0.2
    * CVE-2026-5734 (bmo#2022369, bmo#2023026, bmo#2023545, bmo#2023555,
      bmo#2023958, bmo#2025422, bmo#2025468, bmo#2025492, bmo#2025505)
      Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird
      ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2
* Mon Mar 23 2026 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 140.9.0 ESR
    MFSA 2026-24 (bsc#1260083)
    * CVE-2026-3889 (bmo#2020723)
      Spoofing issue in Thunderbird
    * CVE-2026-4371 (bmo#2023493)
      Out of bounds read in IMAP parsing
    * CVE-2026-4684 (bmo#2011129)
      Race condition, use-after-free in the Graphics: WebRender component
    * CVE-2026-4685 (bmo#2016349)
      Incorrect boundary conditions in the Graphics: Canvas2D component
    * CVE-2026-4686 (bmo#2016351)
      Incorrect boundary conditions in the Graphics: Canvas2D component
    * CVE-2026-4687 (bmo#2016368)
      Sandbox escape due to incorrect boundary conditions in the
      Telemetry component
    * CVE-2026-4688 (bmo#2016373)
      Sandbox escape due to use-after-free in the Disability Access
      APIs component
    * CVE-2026-4689 (bmo#2016374)
      Sandbox escape due to incorrect boundary conditions, integer
      overflow in the XPCOM component
    * CVE-2026-4690 (bmo#2016375)
      Sandbox escape due to incorrect boundary conditions, integer
      overflow in the XPCOM component
    * CVE-2026-4691 (bmo#2017512)
      Use-after-free in the CSS Parsing and Computation component
    * CVE-2026-4692 (bmo#2017643)
      Sandbox escape in the Responsive Design Mode component
    * CVE-2026-4693 (bmo#2018102)
      Incorrect boundary conditions in the Audio/Video: Playback
      component
    * CVE-2026-4694 (bmo#2018430)
      Incorrect boundary conditions, integer overflow in the
      Graphics component
    * CVE-2026-4695 (bmo#2020030)
      Incorrect boundary conditions in the Audio/Video: Web Codecs
      component
    * CVE-2026-4696 (bmo#2020190)
      Use-after-free in the Layout: Text and Fonts component
    * CVE-2026-4697 (bmo#2020422)
      Incorrect boundary conditions in the Audio/Video: Web Codecs
      component
    * CVE-2026-4698 (bmo#2020906)
      JIT miscompilation in the JavaScript Engine: JIT component
    * CVE-2026-4699 (bmo#2021863)
      Incorrect boundary conditions in the Layout: Text and Fonts
      component
    * CVE-2026-4700 (bmo#2003766)
      Mitigation bypass in the Networking: HTTP component
    * CVE-2026-4701 (bmo#2009303)
      Use-after-free in the JavaScript Engine component
    * CVE-2026-4702 (bmo#2013560)
      JIT miscompilation in the JavaScript Engine component
    * CVE-2026-4704 (bmo#2014868)
      Denial-of-service in the WebRTC: Signaling component
    * CVE-2026-4705 (bmo#2014873)
      Undefined behavior in the WebRTC: Signaling component
    * CVE-2026-4706 (bmo#2015091)
      Incorrect boundary conditions in the Graphics: Canvas2D
      component
    * CVE-2026-4707 (bmo#2015267)
      Incorrect boundary conditions in the Graphics: Canvas2D
      component
    * CVE-2026-4708 (bmo#2015268)
      Incorrect boundary conditions in the Graphics component
    * CVE-2026-4709 (bmo#2016329, bmo#2016342)
      Incorrect boundary conditions in the Audio/Video: GMP
      component
    * CVE-2026-4710 (bmo#2016370)
      Incorrect boundary conditions in the Audio/Video component
    * CVE-2026-4711 (bmo#2017002)
      Use-after-free in the Widget: Cocoa component
    * CVE-2026-4712 (bmo#2017666)
      Information disclosure in the Widget: Cocoa component
    * CVE-2026-4713 (bmo#2018113)
      Incorrect boundary conditions in the Graphics component
    * CVE-2026-4714 (bmo#2018126)
      Incorrect boundary conditions in the Audio/Video component
    * CVE-2026-4715 (bmo#2018405)
      Uninitialized memory in the Graphics: Canvas2D component
    * CVE-2026-4716 (bmo#2018592)
      Incorrect boundary conditions, uninitialized memory in the
      JavaScript Engine component
    * CVE-2026-4717 (bmo#2021695)
      Privilege escalation in the Netmonitor component
    * CVE-2025-59375 (bmo#1988467)
      Denial-of-service in the XML component
    * CVE-2026-4718 (bmo#2014864)
      Undefined behavior in the WebRTC: Signaling component
    * CVE-2026-4719 (bmo#2016367)
      Incorrect boundary conditions in the Graphics: Text component
    * CVE-2026-4720 (bmo#2004652, bmo#2019372, bmo#2021922,
      bmo#2022567, bmo#2022733)
      Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird
      ESR 140.9, Firefox 149 and Thunderbird 149
    * CVE-2026-4721 (bmo#2013762, bmo#2015291, bmo#2016591, bmo#2016661,
      bmo#2016664, bmo#2017303, bmo#2017894, bmo#2018090, bmo#2018196,
      bmo#2018379, bmo#2019112, bmo#2022090, bmo#2022243, bmo#2022351,
      bmo#2022478, bmo#2022676)
      Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR
      140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
* Sat Mar 07 2026 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 140.8.1 ESR
    * Add mail.openpgp.load_untested_gpgme_version to load untested
      GPGME version
  - drop mozilla-bmo1967121.patch because of the upstream change
* Sun Feb 22 2026 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 140.8.0 ESR
    MFSA 2026-17 (boo#1258568)
    * CVE-2026-2757 (bmo#2001637)
      Incorrect boundary conditions in the WebRTC: Audio/Video
      component
    * CVE-2026-2758 (bmo#2009608)
      Use-after-free in the JavaScript: GC component
    * CVE-2026-2759 (bmo#2010933)
      Incorrect boundary conditions in the Graphics: ImageLib
      component
    * CVE-2026-2760 (bmo#2011062)
      Sandbox escape due to incorrect boundary conditions in the
      Graphics: WebRender component
    * CVE-2026-2761 (bmo#2011063)
      Sandbox escape in the Graphics: WebRender component
    * CVE-2026-2762 (bmo#2011649)
      Integer overflow in the JavaScript: Standard Library
      component
    * CVE-2026-2763 (bmo#2012018)
      Use-after-free in the JavaScript Engine component
    * CVE-2026-2764 (bmo#2012608)
      JIT miscompilation, use-after-free in the JavaScript Engine:
      JIT component
    * CVE-2026-2765 (bmo#2013562)
      Use-after-free in the JavaScript Engine component
    * CVE-2026-2766 (bmo#2013583)
      Use-after-free in the JavaScript Engine: JIT component
    * CVE-2026-2767 (bmo#2013741)
      Use-after-free in the JavaScript: WebAssembly component
    * CVE-2026-2768 (bmo#2014101)
      Sandbox escape in the Storage: IndexedDB component
    * CVE-2026-2769 (bmo#2014550)
      Use-after-free in the Storage: IndexedDB component
    * CVE-2026-2770 (bmo#2014585)
      Use-after-free in the DOM: Bindings (WebIDL) component
    * CVE-2026-2771 (bmo#2014593)
      Undefined behavior in the DOM: Core & HTML component
    * CVE-2026-2772 (bmo#2014827)
      Use-after-free in the Audio/Video: Playback component
    * CVE-2026-2773 (bmo#2014832)
      Incorrect boundary conditions in the Web Audio component
    * CVE-2026-2774 (bmo#2014883)
      Integer overflow in the Audio/Video component
    * CVE-2026-2775 (bmo#2015199)
      Mitigation bypass in the DOM: HTML Parser component
    * CVE-2026-2776 (bmo#2015266)
      Sandbox escape due to incorrect boundary conditions in the
      Telemetry component in External Software
    * CVE-2026-2777 (bmo#2015305)
      Privilege escalation in the Messaging System component
    * CVE-2026-2778 (bmo#2016358)
      Sandbox escape due to incorrect boundary conditions in the
      DOM: Core & HTML component
    * CVE-2026-2779 (bmo#1164141)
      Incorrect boundary conditions in the Networking: JAR
      component
    * CVE-2026-2780 (bmo#2007829)
      Privilege escalation in the Netmonitor component
    * CVE-2026-2781 (bmo#2009552)
      Integer overflow in the Libraries component in NSS
    * CVE-2026-2782 (bmo#2010743)
      Privilege escalation in the Netmonitor component
    * CVE-2026-2783 (bmo#2010943)
      Information disclosure due to JIT miscompilation in the
      JavaScript Engine: JIT component
    * CVE-2026-2784 (bmo#2012984)
      Mitigation bypass in the DOM: Security component
    * CVE-2026-2785 (bmo#2013549)
      Invalid pointer in the JavaScript Engine component
    * CVE-2026-2786 (bmo#2013612)
      Use-after-free in the JavaScript Engine component
    * CVE-2026-2787 (bmo#2014560)
      Use-after-free in the DOM: Window and Location component
    * CVE-2026-2788 (bmo#2014824)
      Incorrect boundary conditions in the Audio/Video: GMP
      component
    * CVE-2026-2789 (bmo#2015179)
      Use-after-free in the Graphics: ImageLib component
    * CVE-2026-2790 (bmo#2008426)
      Same-origin policy bypass in the Networking: JAR component
    * CVE-2026-2791 (bmo#2015220)
      Mitigation bypass in the Networking: Cache component
    * CVE-2026-2792 (bmo#2008912, bmo#2010050, bmo#2010275,
      bmo#2012331)
      Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird
      ESR 140.8, Firefox 148 and Thunderbird 148
    * CVE-2026-2793 (bmo#2015196, bmo#2016423, bmo#2016498)
      Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR
      140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148
  - add thunderbird-bmo2006630.patch (bmo#2006630)
* Tue Feb 17 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Thunderbird 140.7.2 ESR
    MFSA 2026-11 (boo#1258231)
    * CVE-2026-2447 (bmo#2014390)
      Heap buffer overflow in libvpx
* Fri Jan 30 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Thunderbird 140.7.1 ESR
    MFSA 2026-08 (bsc#1257397)
    * CVE-2026-0818 (bmo#1881530)
      CSS-based exfiltration of the content from partially
      encrypted emails when allowing remote content
* Thu Jan 15 2026 Andreas Stieger <andreas.stieger@gmx.de>
  - Support using system GnuPG with gpgme 2, boo#1253718 bmo1967121
    add mozilla-bmo1967121.patch
* Wed Jan 14 2026 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 140.7.0 ESR
    MFSA 2026-05 (bsc#1256340)
    * CVE-2026-0877 (bmo#1999257)
      Mitigation bypass in the DOM: Security component
    * CVE-2026-0878 (bmo#2003989)
      Sandbox escape due to incorrect boundary conditions in the
      Graphics: CanvasWebGL component
    * CVE-2026-0879 (bmo#2004602)
      Sandbox escape due to incorrect boundary conditions in the
      Graphics component
    * CVE-2026-0880 (bmo#2005014)
      Sandbox escape due to integer overflow in the Graphics
      component
    * CVE-2026-0882 (bmo#1924125)
      Use-after-free in the IPC component
    * CVE-2025-14327 (bmo#1970743)
      Spoofing issue in the Downloads Panel component
    * CVE-2026-0883 (bmo#1989340)
      Information disclosure in the Networking component
    * CVE-2026-0884 (bmo#2003588)
      Use-after-free in the JavaScript Engine component
    * CVE-2026-0885 (bmo#2003607)
      Use-after-free in the JavaScript: GC component
    * CVE-2026-0886 (bmo#2005658)
      Incorrect boundary conditions in the Graphics component
    * CVE-2026-0887 (bmo#2006500)
      Clickjacking issue, information disclosure in the PDF Viewer
      component
    * CVE-2026-0890 (bmo#2005081)
      Spoofing issue in the DOM: Copy & Paste and Drag & Drop
      component
    * CVE-2026-0891 (bmo#1964722, bmo#2000981, bmo#2003100,
      bmo#2003278)
      Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird
      ESR 140.7, Firefox 147 and Thunderbird 147
* Wed Dec 10 2025 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 140.6.0 ESR
    MFSA 2025-96 (bsc#1254551)
    * CVE-2025-14321 (bmo#1992760)
      Use-after-free in the WebRTC: Signaling component
    * CVE-2025-14322 (bmo#1996473)
      Sandbox escape due to incorrect boundary conditions in the
      Graphics: CanvasWebGL component
    * CVE-2025-14323 (bmo#1996555)
      Privilege escalation in the DOM: Notifications component
    * CVE-2025-14324 (bmo#1996840)
      JIT miscompilation in the JavaScript Engine: JIT component
    * CVE-2025-14325 (bmo#1998050)
      JIT miscompilation in the JavaScript Engine: JIT component
    * CVE-2025-14328 (bmo#1996761)
      Privilege escalation in the Netmonitor component
    * CVE-2025-14329 (bmo#1997018)
      Privilege escalation in the Netmonitor component
    * CVE-2025-14330 (bmo#1997503)
      JIT miscompilation in the JavaScript Engine: JIT component
    * CVE-2025-14331 (bmo#2000218)
      Same-origin policy bypass in the Request Handling component
    * CVE-2025-14333 (bmo#1966501, bmo#1997639)
      Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird
      ESR 140.6, Firefox 146 and Thunderbird 146
* Mon Nov 17 2025 Yoshio Sato <vasua.ukraine@gmail.com>
  - Add build_limit for s390x on SLE16 (bsc#1247774)
    * by Martin Sirringhaus <martin.sirringhaus@suse.com>
* Sun Nov 09 2025 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 140.5.0 ESR
    MFSA 2025-91 (bsc#1253188)
    * CVE-2025-13012 (bmo#1991458)
      Race condition in the Graphics component
    * CVE-2025-13016 (bmo#1992130)
      Incorrect boundary conditions in the JavaScript: WebAssembly
      component
    * CVE-2025-13017 (bmo#1980904)
      Same-origin policy bypass in the DOM: Notifications component
    * CVE-2025-13018 (bmo#1984940)
      Mitigation bypass in the DOM: Security component
    * CVE-2025-13019 (bmo#1988412)
      Same-origin policy bypass in the DOM: Workers component
    * CVE-2025-13013 (bmo#1991945)
      Mitigation bypass in the DOM: Core & HTML component
    * CVE-2025-13020 (bmo#1995686)
      Use-after-free in the WebRTC: Audio/Video component
    * CVE-2025-13014 (bmo#1994241)
      Use-after-free in the Audio/Video component
    * CVE-2025-13015 (bmo#1994164)
      Spoofing issue in Thunderbird
    * fixed: Could not drag and drop ICS file to Today Pane
      (bmo#1992935)
    * fixed: With Thunderbird closed, clicking a 'mailto:' link to
      send signed message failed (bmo#1972857)
    * fixed: Upgrade from 128.x->140.x broke authentication for
      @att.net using Yahoo backend (bmo#1978361)
* Sat Oct 18 2025 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 140.4.0 ESR
    * Account Hub is now disabled by default for second email account
    * Users could not read mail signed with OpenPGP v6 and PQC keys
    * Image preview in Insert Image dialog failed with CSP error for web resources
    * Emptying trash on exit did not work with some providers
    * Thunderbird could crash when applying filters
    * Users were unable to override expired mail server certificate
    * Opening Website header link in RSS feed incorrectly re-encoded
      URL parameters
    MFSA 2025-85 (bsc#1251263)
    * CVE-2025-11708 (bmo#1988931)
      Use-after-free in MediaTrackGraphImpl::GetInstance()
    * CVE-2025-11709 (bmo#1989127)
      Out of bounds read/write in a privileged process triggered by
      WebGL textures
    * CVE-2025-11710 (bmo#1989899)
      Cross-process information leaked due to malicious IPC
      messages
    * CVE-2025-11711 (bmo#1989978)
      Some non-writable Object properties could be modified
    * CVE-2025-11712 (bmo#1979536)
      An OBJECT tag type attribute overrode browser behavior on web
      resources without a content-type
    * CVE-2025-11713 (bmo#1986142)
      Potential user-assisted code execution in “Copy as cURL”
      command
    * CVE-2025-11714 (bmo#1973699, bmo#1989945, bmo#1990970,
      bmo#1991040, bmo#1992113)
      Memory safety bugs fixed in Firefox ESR 115.29, Firefox ESR
      140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144
    * CVE-2025-11715 (bmo#1983838, bmo#1987624, bmo#1988244,
      bmo#1988912, bmo#1989734, bmo#1990085, bmo#1991899)
      Memory safety bugs fixed in Firefox ESR 140.4, Thunderbird
      ESR 140.4, Firefox 144 and Thunderbird 144
* Tue Sep 30 2025 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 140.3.1 ESR
    * several bugfixes listed here
      https://www.thunderbird.net/en-US/thunderbird/140.3.1esr/releasenotes
* Sun Sep 14 2025 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 140.3.0 ESR
    * Right-clicking 'List-ID' -> 'Unsubscribe' created double encoded
      draft subject
    * Thunderbird could crash on startup
    * Thunderbird could crash when importing mail
    * Opening Website header link in RSS feed incorrectly re-encoded
      URL parameters
    MFSA 2025-78 (bsc#1249391)
    * CVE-2025-10527 (bmo#1984825)
      Sandbox escape due to use-after-free in the Graphics:
      Canvas2D component
    * CVE-2025-10528 (bmo#1986185)
      Sandbox escape due to undefined behavior, invalid pointer in
      the Graphics: Canvas2D component
    * CVE-2025-10529 (bmo#1970490)
      Same-origin policy bypass in the Layout component
    * CVE-2025-10532 (bmo#1979502)
      Incorrect boundary conditions in the JavaScript: GC component
    * CVE-2025-10533 (bmo#1980788)
      Integer overflow in the SVG component
    * CVE-2025-10536 (bmo#1981502)
      Information disclosure in the Networking: Cache component
    * CVE-2025-10537 (bmo#1938220, bmo#1980730, bmo#1981280,
      bmo#1981283, bmo#1984505, bmo#1985067)
      Memory safety bugs fixed in Firefox ESR 140.3, Thunderbird
      ESR 140.3, Firefox 143 and Thunderbird 143
* Tue Sep 09 2025 Lubos Kocman <lubos.kocman@suse.com>
  - Fix suse_version check for 16.0
* Mon Sep 08 2025 Yoshio Sato <vasua.ukraine@gmail.com>
  - Build for Leap 16 using gcc13 (gcc14 is unavailable on Leap 16)
* Sat Sep 06 2025 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 140.2.1
    * Users could no longer send using smtp-relay.gmail.com
    * Folder compaction could fail to complete due to folder write errors
    * Creating an event or task from mail failed if the mail was
      opened in a tab
* Wed Aug 20 2025 Martin Sirringhaus <martin.sirringhaus@suse.com>
  - Mozilla Thunderbird 140.2
    * fixed: Users were unable to use Fastmail calendars due to
      missing OAuth settings (bmo#1978192)
    * fixed: Account setup error handling was broken for Account
      hub (bmo#1971303)
    * fixed: Menu bar was hidden after updating from 128esr to
      140esr (bmo#1979002)
    * fixed: Security fixes
    MFSA 2025-72 (bsc#1248162)
    * CVE-2025-9179 (bmo#1979527)
      Sandbox escape due to invalid pointer in the Audio/Video: GMP
      component
    * CVE-2025-9180 (bmo#1979782)
      Same-origin policy bypass in the Graphics: Canvas2D component
    * CVE-2025-9181 (bmo#1977130)
      Uninitialized memory in the JavaScript Engine component
    * CVE-2025-9182 (bmo#1975837)
      Denial-of-service due to out-of-memory in the Graphics:
      WebRender component
    * CVE-2025-9184 (bmo#1929482, bmo#1976376, bmo#1979163,
      bmo#1979955)
      Memory safety bugs fixed in Firefox ESR 140.2, Thunderbird
      ESR 140.2, Firefox 142 and Thunderbird 142
    * CVE-2025-9185 (bmo#1970154, bmo#1976782, bmo#1977166)
      Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR
      128.14, Thunderbird ESR 128.14, Firefox ESR 140.2,
      Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142
* Tue Aug 05 2025 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird ESR 140.1.1
    Fixed
    * Users with attachments open in tabs saw an error on Thunderbird restart
    * Sending from unified or local folder failed if no default account was set
    * Delete button could remove attachment instead of message
    * Message list scrolled back when returning to mail tab after opening a message
* Sat Jul 26 2025 Andreas Schwab <schwab@suse.de>
  - Update memory constraints
* Sat Jul 19 2025 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird ESR 140.1.0
    * New folders were not added alphabetically if folders manually
      reordered beforehand
    * Message archive folder creation could silently stop during async
      folder creation
    MFSA 2025-63 (bsc#1246664)
    * CVE-2025-8027 (bmo#1968423)
      JavaScript engine only wrote partial return value to stack
    * CVE-2025-8028 (bmo#1971581)
      Large branch table could lead to truncated instruction
    * CVE-2025-8029 (bmo#1928021)
      javascript: URLs executed on object and embed tags
    * CVE-2025-8036 (bmo#1960834)
      DNS rebinding circumvents CORS
    * CVE-2025-8037 (bmo#1964767)
      Nameless cookies shadow secure cookies
    * CVE-2025-8030 (bmo#1968414)
      Potential user-assisted code execution in “Copy as cURL” command
    * CVE-2025-8031 (bmo#1971719)
      Incorrect URL stripping in CSP reports
    * CVE-2025-8032 (bmo#1974407)
      XSLT documents could bypass CSP
    * CVE-2025-8038 (bmo#1808979)
      CSP frame-src was not correctly enforced for paths
    * CVE-2025-8039 (bmo#1970997)
      Search terms persisted in URL bar
    * CVE-2025-8033 (bmo#1973990)
      Incorrect JavaScript state machine for generators
    * CVE-2025-8034 (bmo#1970422, bmo#1970422, bmo#1970422, bmo#1970422)
      Memory safety bugs fixed in Firefox ESR 115.26, Firefox ESR
      128.13, Thunderbird ESR 128.13, Firefox ESR 140.1,
      Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141
    * CVE-2025-8040 (bmo#1975058, bmo#1975058, bmo#1975998, bmo#1975998)
      Memory safety bugs fixed in Firefox ESR 140.1, Thunderbird
      ESR 140.1, Firefox 141 and Thunderbird 141
    * CVE-2025-8035 (bmo#1975961, bmo#1975961, bmo#1975961)
      Memory safety bugs fixed in Firefox ESR 128.13, Thunderbird
      ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox
      141 and Thunderbird 141
* Tue Jul 15 2025 Tristan Miller <psychonaut@nothingisreal.com>
  - Mozilla Thunderbird ESR 140.0.1
    MFSA 2025-54
    * CVE-2025-6424 (bmo#1966423)
      Use-after-free in FontFaceSet
    * CVE-2025-6425 (bmo#1717672)
      The WebCompat WebExtension shipped exposed a persistent UUID
    * CVE-2025-6426 (bmo#1964385)
      No warning when opening executable terminal files on macOS
    * CVE-2025-6427 (bmo#1966927)
      connect-src Content Security Policy restriction could be
      bypassed
    * CVE-2025-6429 (bmo#1970658)
      Incorrect parsing of URLs could have allowed embedding of
      youtube.com
    * CVE-2025-6430 (bmo#1971140)
      Content-Disposition header ignored when a file is included in
      an embed or object tag
    * CVE-2025-6432 (bmo#1943804)
      DNS Requests leaked outside of a configured SOCKS proxy
    * CVE-2025-6433 (bmo#1954033)
      WebAuthn would allow a user to sign a challenge on a webpage
      with an invalid TLS certificate
    * CVE-2025-6434 (bmo#1955182)
      HTTPS-Only exception screen lacked anti-clickjacking delay
    * CVE-2025-6435 (bmo#1961777 bmo#1950056)
      Save as in Devtools could download files without sanitizing
      the extension
    * CVE-2025-6436 (bmo#1941377 bmo#1960948 bmo#1966187 bmo#1966505
      bmo#1970764)
      Memory safety bugs fixed in Firefox 140 and Thunderbird 140
  - adapt mozilla-ntlm-full-path.patch for Thunderbird 140.0.1
  - adapt mozilla-silence-no-return-type.patch for Thunderbird
    140.0.1
* Sun Jun 29 2025 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird ESR 128.12.0
    MFSA 2025-55 (bsc#1244670)
    * CVE-2025-6424 (bmo#1966423)
      Use-after-free in FontFaceSet
    * CVE-2025-6425 (bmo#1717672)
      The WebCompat WebExtension shipped exposed a persistent UUID
    * CVE-2025-6426 (bmo#1964385)
      No warning when opening executable terminal files on macOS
    * CVE-2025-6429 (bmo#1970658)
      Incorrect parsing of URLs could have allowed embedding of
      youtube.com
    * CVE-2025-6430 (bmo#1971140)
      Content-Disposition header ignored when a file is included in
      an embed or object tag
* Tue Jun 17 2025 Manfred Hollstein <manfred.h@gmx.net>
  - Use these tools/versions unconditionally, package won't build on
    Tumbleweed with new gcc15 otherwise:
    gcc14, gcc14-c++, cargo1.84, rust1.84
* Mon Jun 09 2025 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird ESR 128.11.1
    MFSA 2025-49
    * CVE-2025-5986 (bmo#1958580, bmo#1968012)
      Unsolicited File Download, Disk Space Exhaustion, and Credential
      Leakage via mailbox:/// Links
* Sun Jun 08 2025 Bernhard Wiedemann <bwiedemann@suse.com>
  - Replace usage of %jobs for reproducible builds (boo#1237231)
* Mon May 26 2025 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird ESR 128.11.0
    MFSA 2025-46 (boo#1243353)
    * CVE-2025-5262 (bmo#1962421)
      Double-free in libvpx encoder
    * CVE-2025-5263 (bmo#1960745)
      Error handling for script execution was incorrectly isolated
      from web content
    * CVE-2025-5264 (bmo#1950001)
      Potential local code execution in “Copy as cURL” command
    * CVE-2025-5265 (bmo#1962301)
      Potential local code execution in “Copy as cURL” command
    * CVE-2025-5266 (bmo#1965628)
      Script element events leaked cross-origin resource status
    * CVE-2025-5267 (bmo#1954137)
      Clickjacking vulnerability could have led to leaking saved
      payment card details
    * CVE-2025-5268 (bmo#1950136, bmo#1958121, bmo#1960499,
      bmo#1962634)
      Memory safety bugs fixed in Firefox 139, Thunderbird 139,
      Firefox ESR 128.11, and Thunderbird 128.11
    * CVE-2025-5269 (bmo#1924108)
      Memory safety bug fixed in Firefox ESR 128.11 and Thunderbird
      128.11
    * fixed: Thunderbird could crash if message copying to Sent
      folder was interrupted (bmo#1965304)
* Wed May 21 2025 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird ESR 128.10.2
    MFSA 2025-40 (boo#1243303)
    * CVE-2025-4918 (bmo#1966612)
      Out-of-bounds access when resolving Promise objects
    * CVE-2025-4919 (bmo#1966614)
      Out-of-bounds access when optimizing linear sums
    * Messages could not be viewed if the profile used a UNC path
    * Visual and UX improvements
* Thu May 15 2025 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Thunderbird ESR 128.10.1:
    MFSA 2025-34 (boo#1243216)
    * CVE-2025-3875 (bmo#1950629)
      Sender Spoofing via Malformed From Header in Thunderbird
    * CVE-2025-3877 (bmo#1958580)
      Unsolicited File Download, Disk Space Exhaustion, and
      Credential Leakage via mailbox:/// Links
    * CVE-2025-3909 (bmo#1958376)
      JavaScript Execution via Spoofed PDF Attachment and file:///
      Link
    * CVE-2025-3932 (bmo#1960412)
      Tracking Links in Attachments Bypassed Remote Content
      Blocking
    * fixed: Standalone message windows/tabs no longer responded
      after folder compaction (bmo#1960349)
    * fixed: Thunderbird could crash when importing Outlook
      messages (bmo#1851297)
    * fixed: Visual and UX improvements (bmo#1960861)
* Sun May 11 2025 Christian Boltz <suse-beta@cboltz.de>
  - build on s390x needs 17G memory - adjust _constraints
* Tue Apr 29 2025 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird ESR 128.10.0
    * Changed color override defaults with high contrast mode on
      macOS and Linux
    * Using Delete column in "Search Messages..." window could delete
      other messages
    MFSA 2025-32 (bsc#1241621)
    * CVE-2025-2817 (bmo#1917536)
      Privilege escalation in Thunderbird Updater
    * CVE-2025-4082 (bmo#1937097)
      WebGL shader attribute memory corruption in Thunderbird for
      macOS
    * CVE-2025-4083 (bmo#1958350)
      Process isolation bypass using "javascript:" URI links in
      cross-origin frames
    * CVE-2025-4084 (bmo#1949994, bmo#1956698, bmo#1960198)
      Potential local code execution in "copy as cURL" command
    * CVE-2025-4087 (bmo#1952465)
      Unsafe attribute access during XPath parsing
    * CVE-2025-4091 (bmo#1951161, bmo#1952105)
      Memory safety bugs fixed in Firefox 138, Thunderbird 138,
      Firefox ESR 128.10, and Thunderbird 128.10
    * CVE-2025-4093 (bmo#1894100)
      Memory safety bug fixed in Firefox ESR 128.10 and Thunderbird
      128.10
* Tue Apr 15 2025 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird ESR 128.9.2
    * Two-factor auth via text or email did not work with Office 365 using Oauth2
    * IRC channel was not visible after restart
    * Global indexing failed when processing email with invalid calendar data
    MFSA 2025-27
    * CVE-2025-3522 (bmo#1955372)
      Leak of hashed Window credentials via crafted attachment URL
    * CVE-2025-2830 (bmo#1956379)
      Information Disclosure of /tmp directory listing
    * CVE-2025-3523 (bmo#1958385)
      User Interface (UI) Misrepresentation of attachment URL
* Sat Apr 05 2025 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird ESR 128.9.1
    * Added delay to built-in notifications when new profile is
      created in offline mode
* Thu Apr 03 2025 Ana Guerrero <ana.guerrero@suse.com>
  - Update to use BuildRequires on clang-devel on Tumbleweed/Factory
    instead of clang18-tools.
* Thu Mar 27 2025 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird ESR 128.9.0
    * Thunderbird now has a notification system for real-time desktop alerts
    * Data corruption occurred when compacting IMAP Drafts folder after
      saving a message
    * Right-clicking "Decrypt and Save As..." on an attachment file failed.
    * Thunderbird could crash when importing mail
    * Sort indicators were missing on the calendar events list
    MFSA 2025-24 (bsc#1240083)
    * CVE-2025-3028 (bmo#1941002)
      Use-after-free triggered by XSLTProcessor
    * CVE-2025-3029 (bmo#1952213)
      URL Bar Spoofing via non-BMP Unicode characters
    * CVE-2025-3030 (bmo#1850615, bmo#1932468, bmo#1942551,
      bmo#1951017, bmo#1951494)
      Memory safety bugs fixed in Firefox 137, Thunderbird 137,
      Firefox ESR 128.9, and Thunderbird 128.9
* Wed Mar 05 2025 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 128.8.0
    * Opening an .EML file in profiles with many folders could take a long time
    * Users with many folders experienced poor performance when resizing
      message panes
    * "Replace" button in compose window was overwritten when the window
      was narrow
    * Export to mobile did not work when "Use default server" was selected
    * "Save Link As" was not working in feed web content
    MFSA 2025-18 (bsc#1237683)
    * CVE-2024-43097 (bmo#1945624)
      Overflow when growing an SkRegion's RunArray
    * CVE-2025-1930 (bmo#1902309)
      AudioIPC StreamData could trigger a use-after-free in the
      Browser process
    * CVE-2025-1931 (bmo#1944126)
      Use-after-free in WebTransportChild
    * CVE-2025-1932 (bmo#1944313)
      Inconsistent comparator in XSLT sorting led to out-of-bounds access
    * CVE-2025-1933 (bmo#1946004)
      JIT corruption of WASM i32 return values on 64-bit CPUs
    * CVE-2025-1934 (bmo#1942881)
      Unexpected GC during RegExp bailout processing
    * CVE-2025-1935 (bmo#1866661)
      Clickjacking the registerProtocolHandler info-bar
    * CVE-2025-1936 (bmo#1940027)
      Adding %00 and a fake extension to a jar: URL  changed the
      interpretation of the contents
    * CVE-2025-1937 (bmo#1938471, bmo#1940716)
      Memory safety bugs fixed in Firefox 136, Thunderbird 136,
      Firefox ESR 115.21, Firefox ESR 128.8, and Thunderbird 128.8
    * CVE-2025-1938 (bmo#1922889, bmo#1935004, bmo#1943586,
      bmo#1943912, bmo#1948111)
      Memory safety bugs fixed in Firefox 136, Thunderbird 136,
      Firefox ESR 128.8, and Thunderbird 128.8
* Wed Feb 19 2025 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 128.7.1
    * Users may not have been notified if messages arrived in multiple
      folders at once
    * Message list scrolled to the wrong place on start-up
    * Unified folders could become unusable instead of being
      automatically rebuilt
    * Some messages may have been threaded incorrectly in unified folders
    * Middle-click autoscroll cursor appeared without arrows instead
      of expected design
* Wed Feb 05 2025 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 128.7.0
    MFSA 2025-10 (bsc#1236539)
    * CVE-2025-1009 (bmo#1936613)
      Use-after-free in XSLT
    * CVE-2025-1010 (bmo#1936982)
      Use-after-free in Custom Highlight
    * CVE-2025-1011 (bmo#1936454)
      A bug in WebAssembly code generation could result in a crash
    * CVE-2025-1012 (bmo#1939710)
      Use-after-free during concurrent delazification
    * CVE-2024-11704 (bmo#1899402)
      Potential double-free vulnerability in PKCS#7 decryption
      handling
    * CVE-2025-1013 (bmo#1932555)
      Potential opening of private browsing tabs in normal browsing
      windows
    * CVE-2025-1014 (bmo#1940804)
      Certificate length was not properly checked
    * CVE-2025-1015 (bmo#1939458)
      Unsanitized address book fields
    * CVE-2025-0510 (bmo#1940570)
      Address of e-mail sender can be spoofed by malicious email
    * CVE-2025-1016 (bmo#1936601, bmo#1936844, bmo#1937694,
      bmo#1938469, bmo#1939583, bmo#1940994)
      Memory safety bugs fixed in Firefox 135, Thunderbird 135,
      Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 115.20,
      and Thunderbird 128.7
    * CVE-2025-1017 (bmo#1926256, bmo#1935471, bmo#1935984)
      Memory safety bugs fixed in Firefox 135, Thunderbird 135,
      Firefox ESR 128.7, and Thunderbird 128.7
* Mon Jan 27 2025 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 128.6.1
    * fixed: Link at about:rights pointed to Firefox privacy policy
      instead of Thunderbird's (bmo#1941998)
    * fixed: POP3 'fetch headers only' and 'get selected messages'
      could delete messages (bmo#1930847)
    * fixed: 'Search Online' checkbox in saved search properties
      was incorrectly disabled (bmo#1937642)
    * fixed: POP3 status message showed incorrect download count
      when messages were deleted (bmo#1935800)
    * fixed: Space bar did not always advance to the next unread
      message (bmo#1468925)
    * fixed: Folder creation or renaming failed due to incorrect
      preference settings (bmo#1911225)
    * fixed: Forwarding/editing S/MIME drafts/templates unusable
      due to regression (bmo#1940605, boo#1236411)
    * fixed: Sort order in 'Search Messages' panel reset after
      search or on first launch (bmo#1935073)
    * fixed: Reply window added an unnecessary third blank line at
      the top (bmo#1935938)
    * fixed: Thunderbird spell check box did not allow ENTER to
      accept suggested changes (bmo#1935401)
    * fixed: Long email subject lines could overlap window control
      buttons on macOS (bmo#1940201)
    * fixed: Flathub manifest link was not correct (bmo#1907695)
    * fixed: 'Prefer client-side email scheduling' needed to be
      selected twice (bmo#1862400)
    * fixed: Duplicate invitations were sent if CALDAV calendar
      email case did not match (bmo#1889607)
    * fixed: Visual and UX improvements
      (bmo#1875325,bmo#1901846,bmo#1939603,bmo#1855276)
* Wed Jan 08 2025 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 128.6.0
    * New mail notification was not hidden after reading the new message
    * New mail notification could show for the wrong folder, causing
      repeated alerts
    * macOS shortcut CMD+1 did not restore the main window when it was
      minimized
    * Clicking the context menu "Reply" button resulted in "Reply-All"
    * Switching from "All", "Unread", and "Threads with unread" did not work
    * Downloading message headers from a newsgroup could cause a hang
    * Message list performance slow when many updates happened at once
    * "mailto:" links did not apply the compose format of the current identity
    * Authentication failure of AUTH PLAIN or AUTH LOGIN did not fall
      back to USERPASS
    MFSA 2025-05  (bsc#1234991)
    * CVE-2025-0237 (bmo#1915257)
      WebChannel APIs susceptible to confused deputy attack
    * CVE-2025-0238 (bmo#1915535)
      Use-after-free when breaking lines in text
    * CVE-2025-0239 (bmo#1929156)
      Alt-Svc ALPN validation failure when redirected
    * CVE-2025-0240 (bmo#1929623)
      Compartment mismatch when parsing JavaScript JSON module
    * CVE-2025-0241 (bmo#1933023)
      Memory corruption when using JavaScript Text Segmentation
    * CVE-2025-0242 (bmo#1874523, bmo#1926454, bmo#1931873, bmo#1932169)
      Memory safety bugs fixed in Firefox 134, Thunderbird 134,
      Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19,
      and Thunderbird 128.6
    * CVE-2025-0243 (bmo#1827142, bmo#1932783)
      Memory safety bugs fixed in Firefox 134, Thunderbird 134,
      Firefox ESR 128.6, and Thunderbird 128.6
* Wed Dec 11 2024 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 128.5.2
    * Large virtual folders could be very slow
    * Message could disappear after moving from IMAP folder followed
      by Undo and Redo
    * XMPP chat did not display messages sent inside a CDATA element
    * Selected calendar day did not move forward at midnight
    * Today pane agenda sometimes scrolled for no apparent reason
    * CalDAV calendars without offline support could degrade start-up
      performance
    * Visual and UX improvements
    MFSA 2024-69
    * CVE-2024-50336 (bmo#1929264)
      matrix-js-sdk has insufficient MXC URI validation which could
      allow client-side path traversal
* Tue Dec 03 2024 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 128.5.1
    * Add end of year donation appeal
    * Total message count for favorite folders did not work consistently
* Thu Nov 28 2024 Wolfgang Rosenauer <wr@rosenauer.org>
  - make spec compatible with rpm < 4.17 again
  - correct appdata for different desktop filename
* Tue Nov 26 2024 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 128.5.0
    * IMAP could crash when reading cached messages
    * Enabling "Show Folder Size" on Maildir profile could render
      Thunderbird unusable
    * Messages corrupted by folder compaction were only fixed by user
      intervention
    * Reading a message from past the end of an mbox file did not
      cause an error
    * View -> Folders had duplicate F access keys
    * Add-ons adding columns to the message list could fail and cause
      display issue
    * "Empty trash on exit" and "Expunge inbox on exit" did not
      always work
    * Selecting a display option in View -> Tasks did not apply in
      the Task interface
    MFSA 2024-68 (bsc#1233695)
    * CVE-2024-11691 (bmo#1914707, bmo#1924184)
      Memory corruption in Apple GPU drivers
    * CVE-2024-11692 (bmo#1909535)
      Select list elements could be shown over another site
    * CVE-2024-11693 (bmo#1921458)
      Download Protections were bypassed by .library-ms files on Windows
    * CVE-2024-11694 (bmo#1924167)
      CSP Bypass and XSS Exposure via Web Compatibility Shims
    * CVE-2024-11695 (bmo#1925496)
      URL Bar Spoofing via Manipulated Punycode and Whitespace Characters
    * CVE-2024-11696 (bmo#1929600)
      Unhandled Exception in Add-on Signature Verification
    * CVE-2024-11697 (bmo#1842187)
      Improper Keypress Handling in Executable File Confirmation Dialog
    * CVE-2024-11698 (bmo#1916152)
      Fullscreen Lock-Up When Modal Dialog Interrupts Transition on macOS
    * CVE-2024-11699 (bmo#1880582, bmo#1929911)
      Memory safety bugs fixed in Firefox 133, Thunderbird 133,
      Firefox ESR 128.5, and Thunderbird 128.5
  - appid is thunderbird-esr currently; use the matching desktop
    file name (boo#1233650)
* Wed Nov 20 2024 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 128.4.4
    * QR codes were not scannable by Android app when using most
      high-contrast themes
    * Primary password prompt cancellation during mobile export was
      confusing
  - revert using xdg-desktop-portal as some desktops have limited
    support
* Sat Nov 09 2024 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 128.4.3
    Fixes:
    * Folder corruption could cause Thunderbird to freeze and become unusable
    * Message corruption could be propagated when reading mbox
    * Folder compaction was not abandoned on shutdown
    * Folder compaction did not clean up on failure
    * Collapsed NNTP thread incorrectly indicated there were unread messages
    * Navigating to next unread message did not wait for all messages
      to be loaded
    * Applying column view to folder and children could break if folder
      error occurred
    * Remote content notifications were broken with encrypted messages
    * Updating criteria of a saved search resulted in poor search performance
    * Drop-downs may not work in some places
    MFSA 2024-61
    * CVE-2024-11159 (bmo#1925929)
      Potential disclosure of plaintext in OpenPGP encrypted message
  - remove kmozillahelper support (boo#1226112)
    * removed mozilla-kde.patch
    * requires xdg-desktop-portal instead
* Wed Nov 06 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Thunderbird 128.4.2
    * Increased the auto-compaction threshold to reduce the frequency
      of compaction (bmo#1927656)
    * fixed: New profile creation caused console errors (bmo#1912675)
    * fixed: Repair folder could result in older messages showing
      wrong date and time (bmo#1911916)
    * fixed: Recently deleted messages could become undeleted if
      message compaction failed (bmo#1924927)
    * fixed: Visual and UX improvements
      (bmo#1857413,bmo#1922934,bmo#1924437)
    * fixed: Clicking on an HTML button could cause Thunderbird to
      freeze (bmo#1879355)
    * fixed: Messages could not be selected for dragging
      (bmo#1887518)
    * fixed: Could not open attached file in a MIME encrypted
      message (bmo#1924637)
    * fixed: Account creation "Setup Documentation" link was broken
      (bmo#1925493)
    * fixed: Unable to generate QR codes when exporting to mobile
      in some cases (bmo#1928114)
    * fixed: Operating system reauthentication was missing when
      exporting QR codes for mobile (bmo#1928232)
    * fixed: Could not drag all-day events from one day to another
      in week view (bmo#1922944)
* Sat Nov 02 2024 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 128.4.1
    * Add the 20 year donation appeal (bmo#192538)
* Wed Oct 30 2024 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 128.4.0
    * Export Thunderbird account settings to Thunderbird Mobile via QRCode
    Bugfixes:
    * Unable to send an unencrypted response to an OpenPGP encrypted message
    MFSA 2024-58 (bsc#1231879)
    * CVE-2024-10458 (bmo#1921733)
      Permission leak via embed or object elements
    * CVE-2024-10459 (bmo#1919087)
      Use-after-free in layout with accessibility
    * CVE-2024-10460 (bmo#1912537)
      Confusing display of origin for external protocol handler prompt
    * CVE-2024-10461 (bmo#1914521)
      XSS due to Content-Disposition being ignored in
      multipart/x-mixed-replace response
    * CVE-2024-10462 (bmo#1920423)
      Origin of permission prompt could be spoofed by long URL
    * CVE-2024-10463 (bmo#1920800)
      Cross origin video frame leak
    * CVE-2024-10464 (bmo#1913000)
      History interface could have been used to cause a Denial of
      Service condition in the browser
    * CVE-2024-10465 (bmo#1918853)
      Clipboard "paste" button persisted across tabs
    * CVE-2024-10466 (bmo#1924154)
      DOM push subscription message could hang Firefox
    * CVE-2024-10467 (bmo#1829029, bmo#1888538, bmo#1900394, bmo#1904059,
      bmo#1917742, bmo#1919809, bmo#1923706)
      Memory safety bugs fixed in Firefox 132, Thunderbird 132,
      Firefox ESR 128.4, and Thunderbird 128.4
* Wed Oct 23 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Thunderbird 128.3.3
    * Files left over from failed folder compactions could use up
      disk space (bmo#1878541)
    * Message list returned to selected message after action on
      another message (bmo#1917485)
    * Some faulty messages were downloaded and never stored
      (bmo#1923765)
    * Messages could become corrupted during folder compaction
      (bmo#1923747,bmo#1923541,bmo#1720047)
    * Searching events by Location, Description, or URL failed
      (bmo#1912710)
    * "Remove All Shown" saved passwords deleted all logins if
      filtered without results (bmo#601447)
    * Calendar event updates were not always sent to attendees
      (bmo#1877640)
* Wed Oct 16 2024 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 128.3.2
    bugfix release:
    https://www.thunderbird.net/en-US/thunderbird/128.3.2esr/releasenotes
  - bring back mozilla-bmo531915.patch to fix x86
* Thu Oct 10 2024 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 128.3.1
    https://www.thunderbird.net/en-US/thunderbird/128.0esr/releasenotes/
    and following release notes for minor version updates
    MFSA 2024-52  (bsc#1231413)
    * CVE-2024-9680 (bmo#1923344)
      Use-after-free in Animation timeline
    Mozilla Thunderbird 128.3.0
    MFSA 2024-32 (128.0)
    MFSA 2024-37 (128.1)
    MFSA 2024-43 (128.2)
    MFSA 2024-49 (128.3) (bsc#1230979)
    * CVE-2024-9392 (bmo#1899154, bmo#1905843)
      Compromised content process can bypass site isolation
    * CVE-2024-9393 (bmo#1918301)
      Cross-origin access to PDF contents through multipart responses
    * CVE-2024-9394 (bmo#1918874)
      Cross-origin access to JSON contents through multipart responses
    * CVE-2024-8900 (bmo#1872841)
      Clipboard write permission bypass
    * CVE-2024-9396 (bmo#1912471)
      Potential memory corruption may occur when cloning certain objects
    * CVE-2024-9397 (bmo#1916659)
      Potential directory upload bypass via clickjacking
    * CVE-2024-9398 (bmo#1881037)
      External protocol handlers could be enumerated via popups
    * CVE-2024-9399 (bmo#1907726)
      Specially crafted WebTransport requests could lead to denial
      of service
    * CVE-2024-9400 (bmo#1915249)
      Potential memory corruption during JIT compilation
    * CVE-2024-9401 (bmo#1872744, bmo#1897792, bmo#1911317, bmo#1916476)
      Memory safety bugs fixed in Firefox 131, Firefox ESR 115.16,
      Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3
    * CVE-2024-9402 (bmo#1872744, bmo#1897792, bmo#1911317, bmo#1913445,
      bmo#1914106, bmo#1914475, bmo#1914963, bmo#1915008, bmo#1916476)
      Memory safety bugs fixed in Firefox 131, Firefox ESR 128.3,
      Thunderbird 131, and Thunderbird 128.3
  - removed obsolete patches
    mozilla-bmo1504834-part3.patch
    mozilla-bmo1512162.patch
    mozilla-bmo1775202.patch
    mozilla-bmo531915.patch
    mozilla-fix-aarch64-libopus.patch
    mozilla-fix-issues-with-llvm18.patch
    mozilla-fix-top-level-asm.patch
    mozilla-partial-revert-1768632.patch
    mozilla-rust-disable-future-incompat.patch
    thunderbird-fix-CVE-2024-34703.patch
  - new patch thunderbird-silence-no-return.patch
  - rebased
    mozilla-bmo1504834-part1.patch
    mozilla-kde.patch
    mozilla-libavcodec58_91.patch
    mozilla-silence-no-return-type.patch
* Fri Sep 06 2024 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.15.0
    MFSA 2024-44 (bsc#1229821)
    * CVE-2024-8381 (bmo#1912715)
      Type confusion when looking up a property name in a "with"
      block
    * CVE-2024-8382 (bmo#1906744)
      Internal event interfaces were exposed to web content when
      browser EventHandler listener callbacks ran
    * CVE-2024-8384 (bmo#1911288)
      Garbage collection could mis-color cross-compartment objects
      in OOM conditions
* Thu Aug 29 2024 Manfred Hollstein <manfred.h@gmx.net>
  - Use gcc13 on Tumbleweed and where it is available.
  - Don't use gcc14 as sources don't compile.
* Fri Aug 02 2024 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.14.0
    * When using an external installation of GnuPG, Thunderbird
      occassionally sent/received corrupted messages (bmo#1898832)
    * Users of external GnuPG were unable to decrypt incorrectly
      encoded messages (bmo#1906903)
    MFSA 2024-38 (bsc#1228648)
    * CVE-2024-7519 (bmo#1902307)
      Out of bounds memory access in graphics shared memory handling
    * CVE-2024-7521 (bmo#1904644)
      Incomplete WebAssembly exception handing
    * CVE-2024-7522 (bmo#1906727)
      Out of bounds read in editor component
    * CVE-2024-7525 (bmo#1909298)
      Missing permission check when creating a StreamFilter
    * CVE-2024-7526 (bmo#1910306)
      Uninitialized memory used by WebGL
    * CVE-2024-7527 (bmo#1871303)
      Use-after-free in JavaScript garbage collection
    * CVE-2024-7529 (bmo#1903187)
      Document content could partially obscure security prompts
* Wed Jul 10 2024 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.13.0
    * After starting Thunderbird, the message list position was
      sometimes set to an incorrect position
    MFSA 2024-30 (bsc#1226316)
    * CVE-2024-6600 (bmo#1888340)
      Memory corruption in WebGL API
    * CVE-2024-6601 (bmo#1890748)
      Race condition in permission assignment
    * CVE-2024-6602 (bmo#1895032)
      Memory corruption in NSS
    * CVE-2024-6603 (bmo#1895081)
      Memory corruption in thread creation
    * CVE-2024-6604 (bmo#1748105, bmo#1837550, bmo#1884266)
      Memory safety bugs fixed in Firefox 128, Firefox ESR 115.13,
      and Thunderbird 115.13
* Tue Jul 02 2024 Martin Sirringhaus <martin.sirringhaus@suse.com>
  - Mozilla Thunderbird 115.12.2
    * fixed: Annual Thunderbird Beta appeal intended for
      Thunderbird 115.12.0 did not open as expected (bmo#1898084)
  - Mozilla Thunderbird 115.12.1
    * 115.12.0 got pulled because of upstream automation process errors
      and Windows installer signing changes.
      No code changes, changelog is the same as 115.12.0 (bsc#1226495)
  - Added thunderbird-fix-CVE-2024-34703.patch (bsc#1227239)
* Mon Jun 17 2024 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.12.0
    https://www.thunderbird.net/en-US/thunderbird/115.12.0/releasenotes
    MFSA 2024-28 (bsc#1226027)
    * CVE-2024-5702 (bmo#1193389)
      Use-after-free in networking
    * CVE-2024-5688 (bmo#1895086)
      Use-after-free in JavaScript object transplant
    * CVE-2024-5690 (bmo#1883693)
      External protocol handlers leaked by timing attack
    * CVE-2024-5691 (bmo#1888695)
      Sandboxed iframes were able to bypass sandbox restrictions to
      open a new window
    * CVE-2024-5692 (bmo#1891234)
      Bypass of file name restrictions during saving
    * CVE-2024-5693 (bmo#1891319)
      Cross-Origin Image leak via Offscreen Canvas
    * CVE-2024-5696 (bmo#1896555)
      Memory Corruption in Text Fragments
    * CVE-2024-5700 (bmo#1862809, bmo#1889355, bmo#1893388, bmo#1895123)
      Memory safety bugs fixed in Firefox 127, Firefox ESR 115.12,
      and Thunderbird 115.12
* Wed May 29 2024 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.11.1
    * Added a short anonymous survey that a small number of users will
      be randomly asked to complete
* Tue May 14 2024 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.11.0
    MFSA 2024-23 (bsc#1224056)
    * CVE-2024-4367 (bmo#1893645)
      Arbitrary JavaScript execution in PDF.js
    * CVE-2024-4767 (bmo#1878577)
      IndexedDB files retained in private browsing mode
    * CVE-2024-4768 (bmo#1886082)
      Potential permissions request bypass via clickjacking
    * CVE-2024-4769 (bmo#1886108)
      Cross-origin responses could be distinguished between script
      and non-script content-types
    * CVE-2024-4770 (bmo#1893270)
      Use-after-free could occur when printing to PDF
    * CVE-2024-4777 (bmo#1878199, bmo#1893340)
      Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11,
      and Thunderbird 115.11
* Sat May 04 2024 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Thunderbird 115.10.2:
    https://www.thunderbird.net/en-US/thunderbird/115.10.2/releasenotes/
    This release is identical to 115.10.1, other than changing the
    Update channel for self-updating builds to ESR. (bmo#1893271)
* Fri Apr 19 2024 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.10.1
    https://www.thunderbird.net/en-US/thunderbird/115.10.1/releasenotes/
    * fixed hangup introduced with 115.10.0 (bmo#1891889)
* Sun Apr 14 2024 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.10.0
    https://www.thunderbird.net/en-US/thunderbird/115.10.0/releasenotes/
    MFSA 2024-20 (bsc#1222535)
    * CVE-2024-3852 (bmo#1883542)
      GetBoundName in the JIT returned the wrong object
    * CVE-2024-3854 (bmo#1884552)
      Out-of-bounds-read after mis-optimized switch statement
    * CVE-2024-3857 (bmo#1886683)
      Incorrect JITting of arguments led to use-after-free during
      garbage collection
    * CVE-2024-2609 (bmo#1866100)
      Permission prompt input delay could expire when not in focus
    * CVE-2024-3859 (bmo#1874489)
      Integer-overflow led to out-of-bounds-read in the OpenType sanitizer
    * CVE-2024-3861 (bmo#1883158)
      Potential use-after-free due to AlignedBuffer self-move
    * CVE-2024-3863 (bmo#1885855)
      Download Protections were bypassed by .xrm-ms files on Windows
    * CVE-2024-3302 (bmo#1881183)
      Denial of Service using HTTP/2 CONTINUATION frames
    * CVE-2024-3864 (bmo#1888333)
      Memory safety bug fixed in Firefox 125, Firefox ESR 115.10,
      and Thunderbird 115.10
* Wed Mar 20 2024 Manfred Hollstein <manfred.h@gmx.net>
  - LLVM18 breaks building Thunderbird on Tumbleweed; add
    * mozilla-fix-issues-with-llvm18.patch
* Sat Mar 16 2024 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.9.0
    https://www.thunderbird.net/en-US/thunderbird/115.9.0/releasenotes/
    MFSA 2024-14 (bsc#1221327)
    * CVE-2024-0743 (bmo#1867408)
      Crash in NSS TLS method
    * CVE-2024-2605 (bmo#1872920)
      Windows Error Reporter could be used as a Sandbox escape vector
    * CVE-2024-2607 (bmo#1879939)
      JIT code failed to save return registers on Armv7-A
    * CVE-2024-2608 (bmo#1880692)
      Integer overflow could have led to out of bounds write
    * CVE-2024-2616 (bmo#1846197)
      Improve handling of out-of-memory conditions in ICU
    * CVE-2023-5388 (bmo#1780432)
      NSS susceptible to timing attack against RSA decryption
    * CVE-2024-2610 (bmo#1871112)
      Improper handling of html and body tags enabled CSP nonce leakage
    * CVE-2024-2611 (bmo#1876675)
      Clickjacking vulnerability could have led to a user accidentally
      granting permissions
    * CVE-2024-2612 (bmo#1879444)
      Self referencing object could have potentially led to a use-
      after-free
    * CVE-2024-2614 (bmo#1685358, bmo#1861016, bmo#1880405, bmo#1881093)
      Memory safety bugs fixed in Firefox 124, Firefox ESR 115.9,
      and Thunderbird 115.9
* Tue Mar 05 2024 Adam Mizerski <adam@mizerski.pl>
  - Create subpackage MozillaThunderbird-openpgp-librnp
* Tue Mar 05 2024 Wolfgang Rosenauer <wr@@rosenauer.org>
  - Mozilla Thunderbird 115.8.1
    https://www.thunderbird.net/en-US/thunderbird/115.8.1/releasenotes/
    MFSA 2024-11
    * CVE-2024-1936 (bmo#1860977)
      Leaking of encrypted email subjects to other conversations
* Mon Feb 19 2024 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.8.0
    MFSA 2024-07 (bsc#1220048)
    * CVE-2024-1546 (bmo#1843752)
      Out-of-bounds memory read in networking channels
    * CVE-2024-1547 (bmo#1877879)
      Alert dialog could have been spoofed on another site
    * CVE-2024-1548 (bmo#1832627)
      Fullscreen Notification could have been hidden by select
      element
    * CVE-2024-1549 (bmo#1833814)
      Custom cursor could obscure the permission dialog
    * CVE-2024-1550 (bmo#1860065)
      Mouse cursor re-positioned unexpectedly could have led to
      unintended permission grants
    * CVE-2024-1551 (bmo#1864385)
      Multipart HTTP Responses would accept the Set-Cookie header
      in response parts
    * CVE-2024-1552 (bmo#1874502)
      Incorrect code generation on 32-bit ARM devices
    * CVE-2024-1553 (bmo#1855686, bmo#1867982, bmo#1871498,
      bmo#1872296, bmo#1873521, bmo#1873577, bmo#1873597,
      bmo#1873866, bmo#1874080, bmo#1874740, bmo#1875795,
      bmo#1875906, bmo#1876425, bmo#1878211, bmo#1878286)
      Memory safety bugs fixed in Firefox 123, Firefox ESR 115.8,
      and Thunderbird 115.8
    * new: Added option to show packet dump when OpenPGP fails to
      decrypt (bmo#1874504)
    * fixed: Thunderbird slowed down significantly when opening
      email files (.eml) (bmo#1863957)
    * fixed: Inbox view intermittently reverted to default view
      after moving or deleting messages (bmo#1725127)
    * fixed: Size of collapsed folders in folder pane did not
      include size of subfolders (bmo#1870641)
    * fixed: Hovering over folder does not always expand subfolders
      (bmo#1873101)
    * fixed: Switching to thread pane of a folder using keyboard
      navigation did not focus top message (bmo#1869557)
    * fixed: Clicking "Sent unsent messages" in Outbox context menu
      while in offline mode did not prompt user to go online
      (bmo#1873487)
    * fixed: Mail tab-specific Unified Toolbar buttons received
      focus incorrectly (bmo#1872239)
    * fixed: Quick Filter settings did not persist when Quick
      Filter bar was turned off (bmo#1850266)
    * fixed: Quick Filters were unusually slow (bmo#1849650)
    * fixed: OpenPGP Key Manager filtering did not work
      (bmo#1873655)
    * fixed: OpenPGP sometimes attempted to decrypt message with
      incorrect key (bmo#1865620)
    * fixed: Autoconfig failed on servers that did not support
      OAuth2 (bmo#1869122)
    * fixed: Opening different attachments with the same name in
      different messages could cause attachment files to become
      conflated (bmo#1873023)
    * fixed: Overflowed attachment list could not be scrolled
      (bmo#1871343)
    * fixed: Passwords disappeared from password manager list after
      applying and clearing filters (bmo#1874646)
    * fixed: Cookies in cookie manager list disappeared after
      applying and then clearing filters (bmo#1876733)
* Sun Jan 21 2024 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.7.0
    https://www.thunderbird.net/en-US/thunderbird/115.7.0/releasenotes/
    MFSA 2024-04 (bsc#1218955)
    * CVE-2024-0741 (bmo#1864587)
      Out of bounds write in ANGLE
    * CVE-2024-0742 (bmo#1867152)
      Failure to update user input timestamp
    * CVE-2024-0746 (bmo#1660223)
      Crash when listing printers on Linux
    * CVE-2024-0747 (bmo#1764343)
      Bypass of Content Security Policy when directive unsafe-inline was set
    * CVE-2024-0749 (bmo#1813463)
      Phishing site popup could show local origin in address bar
    * CVE-2024-0750 (bmo#1863083)
      Potential permissions request bypass via clickjacking
    * CVE-2024-0751 (bmo#1865689)
      Privilege escalation through devtools
    * CVE-2024-0753 (bmo#1870262)
      HSTS policy on subdomain could bypass policy of upper domain
    * CVE-2024-0755 (bmo#1868456, bmo#1871445, bmo#1873701)
      Memory safety bugs fixed in Firefox 122, Firefox ESR 115.7,
      and Thunderbird 115.7
* Wed Jan 10 2024 Martin Sirringhaus <martin.sirringhaus@suse.com>
  - Mozilla Thunderbird 115.6.1
    https://www.thunderbird.net/en-US/thunderbird/115.6.1/releasenotes/
    * new: OAuth2 now supported for comcast.net (bmo#1844810)
    * fixed: High CPU usage sometimes occurred with IMAP CONDSTORE
      (conditional STORE) enabled (bmo#1839256)
    * fixed: Replying to a collapsed thread via keyboard shortcut
      (Ctrl+R/Cmd+R) opened a reply for every message in the thread
      (bmo#1866819)
    * fixed: Enabling Grouped By view after reversing sort order of
      column header caused messages to be grouped incorrectly
      (bmo#1868794)
    * fixed: Opening thread pane context menu via keyboard did not
      always scroll view to selection (bmo#1867532)
    * fixed: New mail indicator for POP3 accounts did not indicate
      new messages ready to be downloaded (bmo#1870619)
    * fixed: Messages could not be moved to folders using Message >
      Move To if text or a link in the message had been clicked on
      first (bmo#1868474)
    * fixed: MIME part boundaries were not properly terminated
      (bmo#1805558)
* Sun Dec 17 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.6.0
    https://www.thunderbird.net/en-US/thunderbird/115.6.0/releasenotes/
    * Message selection misbehaved after selecting a sub-message in an
      expanded thread, collapsing the thread, then pressing up/down to
      move selection
    * Thunderbird now attempts to reconnect on a new connection after
      SMTP 4xx errors
    * HTML FileLink attachments used the wrong encoding
    MFSA 2023-55 (bsc#1217230)
    * CVE-2023-50762 (bmo#1862625)
      Truncated signed text was shown with a valid OpenPGP
      signature
    * CVE-2023-50761 (bmo#1865647)
      S/MIME signature accepted despite mismatching message date
    * CVE-2023-6856 (bmo#1843782)
      Heap-buffer-overflow affecting WebGL DrawElementsInstanced
      method with Mesa VM driver
    * CVE-2023-6857 (bmo#1796023)
      Symlinks may resolve to smaller than expected buffers
    * CVE-2023-6858 (bmo#1826791)
      Heap buffer overflow in nsTextFragment
    * CVE-2023-6859 (bmo#1840144)
      Use-after-free in PR_GetIdentitiesLayer
    * CVE-2023-6860 (bmo#1854669)
      Potential sandbox escape due to VideoBridge lack of texture
      validation
    * CVE-2023-6861 (bmo#1864118)
      Heap buffer overflow affected nsWindow::PickerOpen(void) in
      headless mode
    * CVE-2023-6862 (bmo#1868042)
      Use-after-free in nsDNSService
    * CVE-2023-6863 (bmo#1868901)
      Undefined behavior in ShutdownObserver()
    * CVE-2023-6864 (bmo#1736385, bmo#1810805, bmo#1846328,
      bmo#1856090, bmo#1858033, bmo#1858509, bmo#1862089,
      bmo#1862777, bmo#1864015)
      Memory safety bugs fixed in Firefox 121, Firefox ESR 115.6,
      and Thunderbird 115.6
* Tue Dec 12 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.5.2
    Bugfix release
    https://www.thunderbird.net/en-US/thunderbird/115.5.2/releasenotes/
* Tue Nov 28 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.5.1
    Bugfix release
    https://www.thunderbird.net/en-US/thunderbird/115.5.1/releasenotes
    * Advanced GnuPG keys may be protected with an unexpected passphrase
    * OpenPGP signatures rejected due to mismatched signature timestamp
      now display signature timestamp and clarifying message
    * Advanced address book search did not return results if display name
      was left blank
    * Clicking on attendee when inviting attendees added the attendee twice
* Wed Nov 22 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.5.0
    https://www.thunderbird.net/en-US/thunderbird/115.5.0/releasenotes
    MFSA 2023-52 (bsc#1217230)
    * CVE-2023-6204 (bmo#1841050)
      Out-of-bound memory access in WebGL2 blitFramebuffer
    * CVE-2023-6205 (bmo#1854076)
      Use-after-free in MessagePort::Entangled
    * CVE-2023-6206 (bmo#1857430)
      Clickjacking permission prompts using the fullscreen transition
    * CVE-2023-6207 (bmo#1861344)
      Use-after-free in ReadableByteStreamQueueEntry::Buffer
    * CVE-2023-6208 (bmo#1855345)
      Using Selection API would copy contents into X11 primary
      selection.
    * CVE-2023-6209 (bmo#1858570)
      Incorrect parsing of relative URLs starting with "///"
    * CVE-2023-6212 (bmo#1658432, bmo#1820983, bmo#1829252, bmo#1856072,
      bmo#1856091, bmo#1859030, bmo#1860943, bmo#1862782)
      Memory safety bugs fixed in Firefox 120, Firefox ESR 115.5,
      and Thunderbird 115.5
* Wed Nov 15 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.4.3
    Bugfix release
    https://www.thunderbird.net/en-US/thunderbird/115.4.3/releasenotes
* Sat Nov 04 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.4.2
    https://www.thunderbird.net/en-US/thunderbird/115.4.2/releasenotes
  - build using rust/cargo 1.72 (1.69 about to be dropped from Factory)
* Tue Oct 24 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.4.1
    https://www.thunderbird.net/en-US/thunderbird/115.4.1/releasenotes
    https://www.thunderbird.net/en-US/thunderbird/115.4.0/releasenotes
    MFSA 2023-47 (bsc#1216338)
    * CVE-2023-5721 (bmo#1830820)
      Queued up rendering could have allowed websites to clickjack
    * CVE-2023-5732 (bmo#1690979, bmo#1836962)
      Address bar spoofing via bidirectional characters
    * CVE-2023-5724 (bmo#1836705)
      Large WebGL draw could have led to a crash
    * CVE-2023-5725 (bmo#1845739)
      WebExtensions could open arbitrary URLs
    * CVE-2023-5726 (bmo#1846205)
      Full screen notification obscured by file open dialog on macOS
    * CVE-2023-5727 (bmo#1847180)
      Download Protections were bypassed by .msix, .msixbundle,
      .appx, and .appxbundle files on Windows
    * CVE-2023-5728 (bmo#1852729)
      Improper object tracking during GC in the JavaScript engine
      could have led to a crash.
    * CVE-2023-5730 (bmo#1836607, bmo#1840918, bmo#1848694, bmo#1848833,
      bmo#1850191, bmo#1850259, bmo#1852596, bmo#1853201, bmo#1854002,
      bmo#1855306, bmo#1855640, bmo#1856695)
      Memory safety bugs fixed in Firefox 119, Firefox ESR 115.4,
      and Thunderbird 115.4.1
  - removed obsolete mozilla-bmo1846703.patch
* Tue Oct 24 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Thunderbird 115.3.3
    * fixed: "Folder Location" toolbar button did not work for
      local folders (bmo#1843979)
    * fixed: "Copy to <folder name> again" option disappeared from
      context menu after copying to Gmail folder with non-ASCII
      name (bmo#1856712)
    * fixed: Default reply identity did not use "Delivered-To"
      address when catch-all was active (bmo#1815559)
    * fixed: "View Headers All" did not work when selected in
      standalone message window (bmo#1855316)
    * fixed: Viewing the mail filter log displayed an error if no
      log file was present (bmo#1789244)
* Tue Oct 10 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.3.2
    Bugfix release
    https://www.thunderbird.net/en-US/thunderbird/115.3.2/releasenotes
* Fri Sep 29 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.3.1
    MFSA 2023-45 (bsc#1215814)
    * CVE-2023-5217 (bmo#1855550)
      Heap buffer overflow in libvpx
  - Add mozilla-bmo1846703.patch
* Tue Sep 26 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.3.0
    https://www.thunderbird.net/en-US/thunderbird/115.3.0/releasenotes
    MFSA 2023-43 (bsc#1215575)
    * CVE-2023-5168 (bmo#1846683)
      Out-of-bounds write in FilterNodeD2D1
    * CVE-2023-5169 (bmo#1846685)
      Out-of-bounds write in PathOps
    * CVE-2023-5171 (bmo#1851599)
      Use-after-free in Ion Compiler
    * CVE-2023-5174 (bmo#1848454)
      Double-free in process spawning on Windows
    * CVE-2023-5176 (bmo#1836353, bmo#1842674, bmo#1843824,
      bmo#1843962, bmo#1848890, bmo#1850180, bmo#1850983,
      bmo#1851195)
      Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3,
      and Thunderbird 115.3
* Wed Sep 20 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.2.3
    Bugfix release:
    https://www.thunderbird.net/en-US/thunderbird/115.2.3/releasenotes
* Tue Sep 12 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Thunderbird 115.2.2
    https://www.thunderbird.net/en-US/thunderbird/115.2.2/releasenotes
    MFSA 2023-40 (bsc#1215231)
    * CVE-2023-4863 (bmo# bmo#1852649)
      Heap buffer overflow in libwebp
* Tue Sep 12 2023 Andreas Stieger <andreas.stieger@gmx.de>
  - Mozilla Thunderbird 115.2.1
    https://www.thunderbird.net/en-US/thunderbird/115.2.1/releasenotes
    * new: Column separators are now shown between all columns in
      tree view (bmo#1847441)
    * fixed: New mail notification always opened message in message
      pane, even if pane was disabled (bmo#1840092)
    * fixed: After moving an IMAP message to another folder, the
      incorrect message was selected in the message list
      (bmo#1845376)
    * fixed: Adding a tag to an IMAP message opened in a tab failed
      (bmo#1844452)
    * fixed: Junk/Spam folders were not always shown in Unified
      Folders mode (bmo#1838672)
    * fixed: Middle-clicking a folder or message did not open it in
      a background tab, as in previous versions (bmo#1842482)
    * fixed: Settings tab visual improvements: Advanced Fonts
      dialog, Section headers hidden behind search box
      (bmo#1717382,bmo#1846751)
    * fixed: Various visual and style fixes
      (bmo#1843707,bmo#1849823)
* Sun Aug 27 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.2.0
    https://www.thunderbird.net/en-US/thunderbird/115.2.0/releasenotes
    MFSA 2023-38 (bsc#1214606)
    * CVE-2023-4573 (bmo#1846687)
      Memory corruption in IPC CanvasTranslator
    * CVE-2023-4574 (bmo#1846688)
      Memory corruption in IPC ColorPickerShownCallback
    * CVE-2023-4575 (bmo#1846689)
      Memory corruption in IPC FilePickerShownCallback
    * CVE-2023-4576 (bmo#1846694)
      Integer Overflow in RecordedSourceSurfaceCreation
    * CVE-2023-4577 (bmo#1847397)
      Memory corruption in JIT UpdateRegExpStatics
    * CVE-2023-4051 (bmo#1821884)
      Full screen notification obscured by file open dialog
    * CVE-2023-4578 (bmo#1839007)
      Error reporting methods in SpiderMonkey could have triggered
      an Out of Memory Exception
    * CVE-2023-4053 (bmo#1839079)
      Full screen notification obscured by external program
    * CVE-2023-4580 (bmo#1843046)
      Push notifications saved to disk unencrypted
    * CVE-2023-4581 (bmo#1843758)
      XLL file extensions were downloadable without warnings
    * CVE-2023-4582 (bmo#1773874)
      Buffer Overflow in WebGL glGetProgramiv
    * CVE-2023-4583 (bmo#1842030)
      Browsing Context potentially not cleared when closing Private
      Window
    * CVE-2023-4584 (bmo#1843968, bmo#1845205, bmo#1846080,
      bmo#1846526, bmo#1847529)
      Memory safety bugs fixed in Firefox 117, Firefox ESR 102.15,
      Firefox ESR 115.2, Thunderbird 102.15, and Thunderbird 115.2
    * CVE-2023-4585 (bmo#1751583, bmo#1833504, bmo#1841082,
      bmo#1847904, bmo#1848999)
      Memory safety bugs fixed in Firefox 117, Firefox ESR 115.2,
      and Thunderbird 115.2
* Tue Aug 15 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.1.1
    bugfixes as documented here
    https://www.thunderbird.net/en-US/thunderbird/115.1.1/releasenotes
* Tue Aug 01 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 115.1.0
    New major release with Supernova UI
    Releasenotes for 115.0:
    https://www.thunderbird.net/en-US/thunderbird/115.0/releasenotes
    MFSA 2023-33 (bsc#1213746)
    * CVE-2023-4045 (bmo#1833876)
      Offscreen Canvas could have bypassed cross-origin restrictions
    * CVE-2023-4046 (bmo#1837686)
      Incorrect value used during WASM compilation
    * CVE-2023-4047 (bmo#1839073)
      Potential permissions request bypass via clickjacking
    * CVE-2023-4048 (bmo#1841368)
      Crash in DOMParser due to out-of-memory conditions
    * CVE-2023-4049 (bmo#1842658)
      Fix potential race conditions when releasing platform objects
    * CVE-2023-4050 (bmo#1843038)
      Stack buffer overflow in StorageManager
    * CVE-2023-4052 (bmo#1824420)
      File deletion and privilege escalation through Firefox uninstaller
    * CVE-2023-4054 (bmo#1840777)
      Lack of warning when opening appref-ms files
    * CVE-2023-4055 (bmo#1782561)
      Cookie jar overflow caused unexpected cookie jar state
    * CVE-2023-4056 (bmo#1820587, bmo#1824634, bmo#1839235, bmo#1842325,
      bmo#1843847)
      Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1,
      Firefox ESR 102.14, Thunderbird 115.1, and Thunderbird 102.14
    * CVE-2023-4057 (bmo#1841682)
      Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1,
      and Thunderbird 115.1
  - requires NSS 3.90
  - add patches:
    mozilla-rust-disable-future-incompat.patch
    mozilla-partial-revert-1768632.patch
    mozilla-bmo1775202.patch
  - removed obsolete patches:
    gcc13-fix.patch
    mozilla-bmo1568145.patch
    mozilla-bmo1005535.patch
    mozilla-s390x-skia-gradient.patch
  - update create-tar.sh
* Tue Jul 25 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 102.13.1
    MFSA 2023-28
    * CVE-2023-3417 (bmo#1835582, boo#1213658)
      File Extension Spoofing using the Text Direction Override Character
* Fri Jul 07 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 102.13.0
    * Upstream RNP version numbers now recognized as official in about:support
    MFSA 2023-24 (bsc#1212438)
    * CVE-2023-37201 (bmo#1826002)
      Use-after-free in WebRTC certificate generation
    * CVE-2023-37202 (bmo#1834711)
      Potential use-after-free from compartment mismatch in
      SpiderMonkey
    * CVE-2023-37207 (bmo#1816287)
      Fullscreen notification obscured
    * CVE-2023-37208 (bmo#1837675)
      Lack of warning when opening Diagcab files
    * CVE-2023-37211 (bmo#1832306, bmo#1834862, bmo#1835886,
      bmo#1836550, bmo#1837450)
      Memory safety bugs fixed in Firefox 115, Firefox ESR 102.13,
      and Thunderbird 102.13
  - mozilla-llvm16.patch has been applied upstream, remove it here
* Sun Jun 04 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 102.12.0:
    MFSA 2023-21 (bsc#1211922)
    * CVE-2023-34414 (bmo#1695986)
      Click-jacking certificate exceptions through rendering lag
    * CVE-2023-34416 (bmo#1752703, bmo#1818394, bmo#1826875,
      bmo#1827340, bmo#1827655, bmo#1828065, bmo#1830190,
      bmo#1830206, bmo#1830795, bmo#1833339)
      Memory safety bugs fixed in Thunderbird 102.12
    * fixed: "Searching the directory for recipients certificates"
      popup could block compose window when "S/MIME reminder" was
      enabled and using an LDAP address book (bmo#1833651)
    * fixed: Some elements still used animations with "prefers-
      reduced-motion" set (bmo#1833353)
    * fixed: Visual and theme improvements
      (bmo#1832943,bmo#1832990)
* Sat May 27 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 102.11.2
    * fixed: Thunderbird 102.11.1 contained POP3 client regressions
      with offline mode and TLS certificate overrides
      (bmo#1801286,bmo#1816596,bmo#1798785)
  - Includes changes from Thunderbird 102.11.1
    * fixed: POP message retrieval stopped after a network error
      occurred and connectivity was restored (bmo#1798785)
    * fixed: Reused SMTP connections sometimes silently
      disconnected, causing timeouts (bmo#1766382)
    * fixed: Thunderbird could freeze if saving a sent message to
      IMAP failed (bmo#1745130)
    * fixed: Creating OpenPGP keys with no expiration was not
      possible (bmo#1830094)
    * fixed: News reader did not always issue GROUP command after
      authentication with remote server, preventing Thundebird from
      displaying or refreshing news from the server (bmo#1824377)
  - updated mozilla.keyring
* Thu May 11 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 102.11.0
    * https://www.thunderbird.net/en-US/thunderbird/102.11.0/releasenotes
    MFSA 2023-18 (bsc#1211175)
    * CVE-2023-32205 (bmo#1753339, bmo#1753341)
      Browser prompts could have been obscured by popups
    * CVE-2023-32206 (bmo#1824892)
      Crash in RLBox Expat driver
    * CVE-2023-32207 (bmo#1826116)
      Potential permissions request bypass via clickjacking
    * CVE-2023-32211 (bmo#1823379)
      Content process crash due to invalid wasm code
    * CVE-2023-32212 (bmo#1826622)
      Potential spoof due to obscured address bar
    * CVE-2023-32213 (bmo#1826666)
      Potential memory corruption in FileReader::DoReadData()
    * CVE-2023-32214 (bmo#1828716)
      Potential DoS via exposed protocol handlers
    * CVE-2023-32215 (bmo#1540883, bmo#1751943, bmo#1814856,
      bmo#1820210, bmo#1821480, bmo#1827019, bmo#1827024, bmo#1827144,
      bmo#1827359, bmo#1830186)
      Memory safety bugs fixed in Firefox 113 and Firefox ESR 102.11
* Sun Apr 23 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 102.10.1
    * https://www.thunderbird.net/en-US/thunderbird/102.10.1/releasenotes
* Wed Apr 05 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 102.10.0
    * New messages will automatically select S/MIME if configured and
      OpenPGP is not
    * Calendar events with timezone America/Mexico_City incorrectly
      applied Daylight Savings Time
    MFSA 2023-15 (bsc#1210212)
    * CVE-2023-29531 (bmo#1794292)
      Out-of-bound memory access in WebGL on macOS
    * CVE-2023-29532 (bmo#1806394)
      Mozilla Maintenance Service Write-lock bypass
    * CVE-2023-29533 (bmo#1798219, bmo#1814597)
      Fullscreen notification obscured
    * MFSA-TMP-2023-0001 (bmo#1819244)
      Double-free in libwebp
    * CVE-2023-29535 (bmo#1820543)
      Potential Memory Corruption following Garbage Collector compaction
    * CVE-2023-29536 (bmo#1821959)
      Invalid free from JavaScript code
    * CVE-2023-0547 (bmo#1811298)
      Revocation status of S/Mime recipient certificates was not checked
    * CVE-2023-29479 (bmo#1824978)
      Hang when processing certain OpenPGP messages
    * CVE-2023-29539 (bmo#1784348)
      Content-Disposition filename truncation leads to Reflected
      File Download
    * CVE-2023-29541 (bmo#1810191)
      Files with malicious extensions could have been downloaded
      unsafely on Linux
    * CVE-2023-29542 (bmo#1810793, bmo#1815062)
      Bypass of file download extension restrictions
    * CVE-2023-29545 (bmo#1823077)
      Windows Save As dialog resolved environment variables
    * CVE-2023-1945 (bmo#1777588)
      Memory Corruption in Safe Browsing Code
    * CVE-2023-29548 (bmo#1822754)
      Incorrect optimization result on ARM64
    * CVE-2023-29550 (bmo#1720594, bmo#1751945, bmo#1812498, bmo#1814217,
      bmo#1818357, bmo#1818762, bmo#1819493, bmo#1820389, bmo#1820602,
      bmo#1821448, bmo#1822413, bmo#1824828)
      Memory safety bugs fixed in Thunderbird 102.10
  - add mozilla-llvm16.patch to fix build with LLVM16
* Wed Mar 29 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 102.9.1
    MFSA 2023-12
    * CVE-2023-28427 (bmo#1822595)
      Matrix SDK bundled with Thunderbird vulnerable to
      denial-of-service attack
* Sun Mar 26 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - add gcc13-fix.patch to support current Tumbleweed
* Sun Mar 12 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 102.9.0
    * https://www.thunderbird.net/en-US/thunderbird/102.9.0/releasenotes
    MFSA 2023-11 (bsc#1209173))
    * CVE-2023-25751 (bmo#1814899)
      Incorrect code generation during JIT compilation
    * CVE-2023-28164 (bmo#1809122)
      URL being dragged from a removed cross-origin iframe into the
      same tab triggered navigation
    * CVE-2023-28162 (bmo#1811327)
      Invalid downcast in Worklets
    * CVE-2023-25752 (bmo#1811627)
      Potential out-of-bounds when accessing throttled streams
    * CVE-2023-28163 (bmo#1817768)
      Windows Save As dialog resolved environment variables
    * CVE-2023-28176 (bmo#1808352, bmo#1811637, bmo#1815904,
      bmo#1817442, bmo#1818674)
      Memory safety bugs fixed in Thunderbird 102.9
  - update create-tar.sh
  - build using rust 1.67
* Tue Mar 07 2023 Manfred Hollstein <manfred.h@gmx.net>
  - Ensure gcc11-c++ gets used on Leap 15.5, too.
* Wed Feb 15 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 102.8.0
    * https://www.thunderbird.net/en-US/thunderbird/102.8.0/releasenotes
    MFSA 2023-07 (bsc#1208144)
    * CVE-2023-0616 (bmo#1806507)
      User Interface lockup with messages combining S/MIME and OpenPGP
    * CVE-2023-25728 (bmo#1790345)
      Content security policy leak in violation reports using iframes
    * CVE-2023-25730 (bmo#1794622)
      Screen hijack via browser fullscreen mode
    * CVE-2023-0767 (bmo#1804640)
      Arbitrary memory write via PKCS 12 in NSS
    * CVE-2023-25735 (bmo#1810711)
      Potential use-after-free from compartment mismatch in SpiderMonkey
    * CVE-2023-25737 (bmo#1811464)
      Invalid downcast in SVGUtils::SetupStrokeGeometry
    * CVE-2023-25738 (bmo#1811852)
      Printing on Windows could potentially crash Thunderbird with
      some device drivers
    * CVE-2023-25739 (bmo#1811939)
      Use-after-free in mozilla::dom::ScriptLoadContext::~ScriptLoadContext
    * CVE-2023-25729 (bmo#1792138)
      Extensions could have opened external schemes without user knowledge
    * CVE-2023-25732 (bmo#1804564)
      Out of bounds memory write from EncodeInputStream
    * CVE-2023-25734 (bmo#1784451, bmo#1809923, bmo#1810143, bmo#1812338)
      Opening local .url files could cause unexpected network loads
    * CVE-2023-25742 (bmo#1813424)
      Web Crypto ImportKey crashes tab
    * CVE-2023-25746 (bmo#1544127, bmo#1762368, bmo#1789449, bmo#1803628,
      bmo#1810536)
      Memory safety bugs fixed in Thunderbird 102.8
  - requires
    NSPR >= 4.34.1
    NSS  >= 3.79.4
* Wed Feb 08 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 102.7.2
    * Various crash fixes
* Tue Jan 31 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 102.7.1
    * Microsoft Office 365 accounts were unable to authenticate
    * https://www.thunderbird.net/en-US/thunderbird/102.7.1/releasenotes/
    MFSA 2023-04
    * CVE-2023-0430 (bmo#1769000)
      Revocation status of S/Mime signature certificates was not checked
  - update create-tar.sh
* Tue Jan 17 2023 Wolfgang Rosenauer <wr@rosenauer.org>
  - Mozilla Thunderbird 102.7.0
    https://www.thunderbird.net/en-US/thunderbird/102.7.0/releasenotes/
    MFSA 2023-03 (bsc#1207119)
    * CVE-2022-46871 (bmo#1795697)
      libusrsctp library out of date
    * CVE-2023-23598 (bmo#1800425)
      Arbitrary file read from GTK drag and drop on Linux
    * CVE-2023-23599 (bmo#1777800)
      Malicious command could be hidden in devtools output on
      Windows
    * CVE-2023-23601 (bmo#1794268)
      URL being dragged from cross-origin iframe into same tab
      triggers navigation
    * CVE-2023-23602 (bmo#1800890)
      Content Security Policy wasn't being correctly applied to
      WebSockets in WebWorkers
    * CVE-2022-46877 (bmo#1795139)
      Fullscreen notification bypass
    * CVE-2023-23603 (bmo#1800832)
      Calls to <code>console.log</code> allowed bypasing Content
      Security Policy via format directive
    * CVE-2023-23605 (bmo#1764921, bmo#1802690, bmo#1806974)
      Memory safety bugs fixed in Thunderbird 102.7

Files

/usr/bin/thunderbird
/usr/lib64/thunderbird
/usr/lib64/thunderbird/application.ini
/usr/lib64/thunderbird/chrome
/usr/lib64/thunderbird/chrome/icons
/usr/lib64/thunderbird/chrome/icons/default
/usr/lib64/thunderbird/chrome/icons/default/TB-symbolic.svg
/usr/lib64/thunderbird/chrome/icons/default/calendar-alarm-dialog.png
/usr/lib64/thunderbird/chrome/icons/default/calendar-general-dialog.png
/usr/lib64/thunderbird/chrome/icons/default/default128.png
/usr/lib64/thunderbird/chrome/icons/default/default16.png
/usr/lib64/thunderbird/chrome/icons/default/default22.png
/usr/lib64/thunderbird/chrome/icons/default/default24.png
/usr/lib64/thunderbird/chrome/icons/default/default256.png
/usr/lib64/thunderbird/chrome/icons/default/default32.png
/usr/lib64/thunderbird/chrome/icons/default/default48.png
/usr/lib64/thunderbird/chrome/icons/default/default64.png
/usr/lib64/thunderbird/chrome/icons/default/msgcomposeWindow16.png
/usr/lib64/thunderbird/chrome/icons/default/msgcomposeWindow24.png
/usr/lib64/thunderbird/chrome/icons/default/msgcomposeWindow32.png
/usr/lib64/thunderbird/chrome/icons/default/msgcomposeWindow48.png
/usr/lib64/thunderbird/crashhelper
/usr/lib64/thunderbird/crashreporter
/usr/lib64/thunderbird/defaults
/usr/lib64/thunderbird/defaults/messenger
/usr/lib64/thunderbird/defaults/messenger/mailViews.dat
/usr/lib64/thunderbird/defaults/pref
/usr/lib64/thunderbird/defaults/pref/all-l10n.js
/usr/lib64/thunderbird/defaults/pref/all-opensuse.js
/usr/lib64/thunderbird/defaults/pref/channel-prefs.js
/usr/lib64/thunderbird/dependentlibs.list
/usr/lib64/thunderbird/fonts
/usr/lib64/thunderbird/fonts/TwemojiMozilla.ttf
/usr/lib64/thunderbird/glxtest
/usr/lib64/thunderbird/isp
/usr/lib64/thunderbird/isp/Bogofilter.sfd
/usr/lib64/thunderbird/isp/DSPAM.sfd
/usr/lib64/thunderbird/isp/POPFile.sfd
/usr/lib64/thunderbird/isp/SpamAssassin.sfd
/usr/lib64/thunderbird/isp/SpamPal.sfd
/usr/lib64/thunderbird/libgkcodecs.so
/usr/lib64/thunderbird/liblgpllibs.so
/usr/lib64/thunderbird/libmozavcodec.so
/usr/lib64/thunderbird/libmozavutil.so
/usr/lib64/thunderbird/libmozgtk.so
/usr/lib64/thunderbird/libmozsandbox.so
/usr/lib64/thunderbird/libmozsqlite3.so
/usr/lib64/thunderbird/libmozwayland.so
/usr/lib64/thunderbird/libxul.so
/usr/lib64/thunderbird/omni.ja
/usr/lib64/thunderbird/pingsender
/usr/lib64/thunderbird/platform.ini
/usr/lib64/thunderbird/rnp-cli
/usr/lib64/thunderbird/rnpkeys
/usr/lib64/thunderbird/thunderbird-bin
/usr/lib64/thunderbird/thunderbird.sh
/usr/lib64/thunderbird/vaapitest
/usr/share/appdata
/usr/share/appdata/thunderbird-esr.appdata.xml
/usr/share/applications/thunderbird-esr.desktop
/usr/share/icons/hicolor/128x128/apps/thunderbird.png
/usr/share/icons/hicolor/16x16/apps/thunderbird.png
/usr/share/icons/hicolor/22x22/apps/thunderbird.png
/usr/share/icons/hicolor/24x24/apps/thunderbird.png
/usr/share/icons/hicolor/256x256/apps/thunderbird.png
/usr/share/icons/hicolor/32x32/apps/thunderbird.png
/usr/share/icons/hicolor/48x48/apps/thunderbird.png
/usr/share/icons/hicolor/64x64/apps/thunderbird.png
/usr/share/icons/hicolor/symbolic/apps/thunderbird-symbolic.svg


Generated by rpm2html 1.8.1

Fabrice Bellet, Thu Aug 6 22:22:51 2026