Subject: CVS commit: pkgsrc/mail/thunderbird
From: Ryo ONODERA
Date: 2024-10-31 13:34:32
Message id: 20241031123432.9C178FC7E@cvs.NetBSD.org

Log Message:
mail/thunderbird: Update to 128.4.0

Changelog:
128.4.0:
What's New
new
Export Thunderbird account settings to Thunderbird Mobile via QRCode

What's Fixed
fixed
Unable to send an unencrypted response to an OpenPGP encrypted message

fixed
Thunderbird update did not update language pack version until another restart

fixed
Security fixes

Security fixes:
Mozilla Foundation Security Advisory 2024-58
#CVE-2024-10458: Permission leak via embed or object elements
#CVE-2024-10459: Use-after-free in layout with accessibility
#CVE-2024-10460: Confusing display of origin for external protocol handler
 prompt
#CVE-2024-10461: XSS due to Content-Disposition being ignored in multipart/
 x-mixed-replace response
#CVE-2024-10462: Origin of permission prompt could be spoofed by long URL
#CVE-2024-10463: Cross origin video frame leak
#CVE-2024-10464: History interface could have been used to cause a Denial of
 Service condition in the browser
#CVE-2024-10465: Clipboard "paste" button persisted across tabs
#CVE-2024-10466: DOM push subscription message could hang Firefox
#CVE-2024-10467: Memory safety bugs fixed in Firefox 132, Thunderbird 132,
 Firefox ESR 128.4, and Thunderbird 128.4

Files:
RevisionActionfile
1.328modifypkgsrc/mail/thunderbird/Makefile
1.277modifypkgsrc/mail/thunderbird/distinfo
1.1removepkgsrc/mail/thunderbird/patches/patch-python_mozbuild_mozbuild_action_node.py