Path to this page:
Subject: CVS commit: pkgsrc/mail/thunderbird
From: Ryo ONODERA
Date: 2018-07-30 21:51:48
Message id: 20180730195148.19453FBEC@cvs.NetBSD.org
Log Message:
Update to 52.9.1
Changelog:
changed
Thunderbird will now prompt to compact IMAP folders even if the account is \
online. Note: Under certain circumstances an incorrect estimate of the expected \
gain is shown.
fixed
Complete fix of the EFAIL vulnerability: 1) Removing some HTML crafted to \
carry out an attack. 2) Optionally: Not decrypting subordinate message parts \
that otherwise might reveal decrypted content to the attacker. Preference \
mailnews.p7m_subparts_external needs to be set to true for added security.
fixed
Various problems when forwarding messages inline when using \
"simple" HTML view
fixed
Deleting or detaching attachments corrupted messages under certain \
circumstances (not working only in Thunderbird version 52.9.0)
fixed
Various security fixes
Security fixes:
#CVE-2018-12359: Buffer overflow using computed size of canvas element
#CVE-2018-12360: Use-after-free when using focus()
#CVE-2018-12372: S/MIME and PGP decryption oracles can be built with HTML emails
#CVE-2018-12373: S/MIME plaintext can be leaked through HTML reply/forward
#CVE-2018-12362: Integer overflow in SSSE3 scaler
#CVE-2018-12363: Use-after-free when appending DOM nodes
#CVE-2018-12364: CSRF attacks through 307 redirects and NPAPI plugins
#CVE-2018-12365: Compromised IPC child process can list local filenames
#CVE-2018-12366: Invalid data handling during QCMS transformations
#CVE-2018-12368: No warning when opening executable SettingContent-ms files
#CVE-2018-12374: Using form to exfiltrate encrypted mail part by pressing enter \
in form field
#CVE-2018-5188: Memory safety bugs fixed in Firefox 60, Firefox ESR 60.1, \
Firefox ESR 52.9, and Thunderbird 52.9
Files: