Subject: CVS commit: pkgsrc/mail/thunderbird
From: Ryo ONODERA
Date: 2020-03-15 14:28:51
Message id: 20200315132851.630EDFB27@cvs.NetBSD.org

Log Message:
thunderbird: Update to 68.6.0

CVhangelog:
68.6.0
new
Thunderbird now displays a popup window when starting up on a new
profile

changed
Thunderbird now provides partial updates resulting in smaller
downloads

fixed
Searching in message bodies led to false negatives under some
circumstances in quoted-printable encoded HTML bodies

"Get New Messages for All Accounts" not working for OAuth2-authenticated
IMAP accounts

Various security fixes
#CVE-2020-6805: Use-after-free when removing data about origins
#CVE-2020-6806: BodyStream::OnInputStreamReady was missing protections against \ 
state confusion
#CVE-2020-6807: Use-after-free in cubeb during stream destruction
#CVE-2020-6811: Devtools' 'Copy as cURL' feature did not fully escape \ 
website-controlled data, potentially leading to command injection
#CVE-2019-20503: Out of bounds reads in sctp_load_addresses_from_init
#CVE-2020-6812: The names of AirPods with personally identifiable information \ 
were exposed to websites with camera or microphone permission
#CVE-2020-6814: Memory safety bugs fixed in Thunderbird 68.6

68.0.5
new
Support for Client Identity IMAP/SMTP Service Extension

Support for OAuth 2.0 authentication for POP3 accounts

fixed

Files:
RevisionActionfile
1.242modifypkgsrc/mail/thunderbird/Makefile
1.76modifypkgsrc/mail/thunderbird/PLIST
1.223modifypkgsrc/mail/thunderbird/distinfo