Log message:
mail/thunderbird: Update to 128.7.0
Changelog:
128.7.0:
What's Fixed
fixed
Images inside links could zoom when clicked instead of opening the link
fixed
Compacting an empty folder failed with write error
fixed
Compacting of IMAP folder with corrupted local storage failed with write error
fixed
After restart, all restored tabs with opened PDFs showed the same attachment
fixed
Exceptions during CalDAV item processing would halt subsequent item handling
fixed
Context menu was unable to move email address to a different field
fixed
Security fixes
Security fixes:
Mozilla Foundation Security Advisory 2025-10
#CVE-2025-1009: Use-after-free in XSLT
#CVE-2025-1010: Use-after-free in Custom Highlight
#CVE-2025-1011: A bug in WebAssembly code generation could result in a crash
#CVE-2025-1012: Use-after-free during concurrent delazification
#CVE-2024-11704: Potential double-free vulnerability in PKCS#7 decryption
handling
#CVE-2025-1013: Potential opening of private browsing tabs in normal browsing
windows
#CVE-2025-1014: Certificate length was not properly checked
#CVE-2025-1015: Unsanitized address book fields
#CVE-2025-0510: Address of e-mail sender can be spoofed by malicious email
#CVE-2025-1016: Memory safety bugs fixed in Firefox 135, Thunderbird 135,
Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 115.20, and Thunderbird
128.7
#CVE-2025-1017: Memory safety bugs fixed in Firefox 135, Thunderbird 135,
Firefox ESR 128.7, and Thunderbird 128.7
128.6.0:
What's Fixed
fixed
New mail notification was not hidden after reading the new message
fixed
New mail notification could show for the wrong folder, causing repeated alerts
fixed
macOS shortcut CMD+1 did not restore the main window when it was minimized
fixed
Clicking the context menu "Reply" button resulted in "Reply-All"
fixed
Switching from "All", "Unread", and "Threads with \
unread" did not work
fixed
Downloading message headers from a newsgroup could cause a hang
fixed
Message list performance slow when many updates happened at once
fixed
"mailto:" links did not apply the compose format of the current identity
fixed
Authentication failure of AUTH PLAIN or AUTH LOGIN did not fall back to
USERPASS
fixed
Security fixes
Security fixes:
Mozilla Foundation Security Advisory 2025-05
#CVE-2025-0237: WebChannel APIs susceptible to confused deputy attack
#CVE-2025-0238: Use-after-free when breaking lines in text
#CVE-2025-0239: Alt-Svc ALPN validation failure when redirected
#CVE-2025-0240: Compartment mismatch when parsing JavaScript JSON module
#CVE-2025-0241: Memory corruption when using JavaScript Text Segmentation
#CVE-2025-0242: Memory safety bugs fixed in Firefox 134, Thunderbird 134,
Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird
128.6
#CVE-2025-0243: Memory safety bugs fixed in Firefox 134, Thunderbird 134,
Firefox ESR 128.6, and Thunderbird 128.6
|
Log message:
mail/thunderbird: Update to 128.5.0
Changelog:
128.5.0:
What's Fixed
fixed
IMAP could crash when reading cached messages
fixed
Enabling "Show Folder Size" on Maildir profile could render Thunderbird
unusable
fixed
Messages corrupted by folder compaction were only fixed by user intervention
fixed
Reading a message from past the end of an mbox file did not cause an error
fixed
View -> Folders had duplicate F access keys
fixed
Add-ons adding columns to the message list could fail and cause display issue
fixed
"Empty trash on exit" and "Expunge inbox on exit" did not \
always work
fixed
Selecting a display option in View -> Tasks did not apply in the Task interface
fixed
Security fixes
Security fixes:
Mozilla Foundation Security Advisory 2024-68
#CVE-2024-11691: Out-of-bounds write in Apple GPU drivers via WebGL
#CVE-2024-11692: Select list elements could be shown over another site
#CVE-2024-11693: Download Protections were bypassed by .library-ms files on
Windows
#CVE-2024-11694: CSP Bypass and XSS Exposure via Web Compatibility Shims
#CVE-2024-11695: URL Bar Spoofing via Manipulated Punycode and Whitespace
Characters
#CVE-2024-11696: Unhandled Exception in Add-on Signature Verification
#CVE-2024-11697: Improper Keypress Handling in Executable File Confirmation
Dialog
#CVE-2024-11698: Fullscreen Lock-Up When Modal Dialog Interrupts Transition on
macOS
#CVE-2024-11699: Memory safety bugs fixed in Firefox 133, Thunderbird 133,
Firefox ESR 128.5, and Thunderbird 128.5
128.4.4:
What's Fixed
fixed
QR codes were not scannable by Android app when using most high-contrast themes
fixed
Primary password prompt cancellation during mobile export was confusing
128.4.3:
What's Fixed
fixed
Folder corruption could cause Thunderbird to freeze and become unusable
fixed
Message corruption could be propagated when reading mbox
fixed
Folder compaction was not abandoned on shutdown
fixed
Folder compaction did not clean up on failure
fixed
Collapsed NNTP thread incorrectly indicated there were unread messages
fixed
Navigating to next unread message did not wait for all messages to be loaded
fixed
Applying column view to folder and children could break if folder error
occurred
fixed
Remote content notifications were broken with encrypted messages
fixed
Updating criteria of a saved search resulted in poor search performance
fixed
Drop-downs may not work in some places
fixed
Security fixes
Security fixes:
Mozilla Foundation Security Advisory 2024-61
#CVE-2024-11159: Potential disclosure of plaintext in OpenPGP encrypted message
128.4.2:
What's Changed
changed
Increased the auto-compaction threshold to reduce frequency of compaction
What's Fixed
fixed
New profile creation caused console errors
fixed
Repair folder could result in older messages showing wrong date and time
fixed
Recently deleted messages could become undeleted if message compaction failed
fixed
Visual and UX improvements
fixed
Clicking on an HTML button could cause Thunderbird to freeze
fixed
Messages could not be selected for dragging
fixed
Could not open attached file in a MIME encrypted message
fixed
Account creation "Setup Documentation" link was broken
fixed
Unable to generate QR codes when exporting to mobile in some cases
fixed
Operating system reauthentication was missing when exporting QR codes for
mobile
fixed
Could not drag all-day events from one day to another in week view
128.4.1:
What's New
new
Add the 20 year donation appeal
|