Subject: CVS commit: pkgsrc/mail/thunderbird
From: Ryo ONODERA
Date: 2018-07-30 21:51:48
Message id: 20180730195148.19453FBEC@cvs.NetBSD.org

Log Message:
Update to 52.9.1

Changelog:
    changed
    Thunderbird will now prompt to compact IMAP folders even if the account is \ 
online. Note: Under certain circumstances an incorrect estimate of the expected \ 
gain is shown.

    fixed
    Complete fix of the EFAIL vulnerability: 1) Removing some HTML crafted to \ 
carry out an attack. 2) Optionally: Not decrypting subordinate message parts \ 
that otherwise might reveal decrypted content to the attacker. Preference \ 
mailnews.p7m_subparts_external needs to be set to true for added security.

    fixed
    Various problems when forwarding messages inline when using \ 
"simple" HTML view

    fixed
    Deleting or detaching attachments corrupted messages under certain \ 
circumstances (not working only in Thunderbird version 52.9.0)

    fixed
    Various security fixes

Security fixes:
#CVE-2018-12359: Buffer overflow using computed size of canvas element
#CVE-2018-12360: Use-after-free when using focus()
#CVE-2018-12372: S/MIME and PGP decryption oracles can be built with HTML emails
#CVE-2018-12373: S/MIME plaintext can be leaked through HTML reply/forward
#CVE-2018-12362: Integer overflow in SSSE3 scaler
#CVE-2018-12363: Use-after-free when appending DOM nodes
#CVE-2018-12364: CSRF attacks through 307 redirects and NPAPI plugins
#CVE-2018-12365: Compromised IPC child process can list local filenames
#CVE-2018-12366: Invalid data handling during QCMS transformations
#CVE-2018-12368: No warning when opening executable SettingContent-ms files
#CVE-2018-12374: Using form to exfiltrate encrypted mail part by pressing enter \ 
in form field
#CVE-2018-5188: Memory safety bugs fixed in Firefox 60, Firefox ESR 60.1, \ 
Firefox ESR 52.9, and Thunderbird 52.9

Files:
RevisionActionfile
1.212modifypkgsrc/mail/thunderbird/Makefile
1.201modifypkgsrc/mail/thunderbird/distinfo