Opened 3 weeks ago

Closed 2 weeks ago

Last modified 2 weeks ago

#15108 closed enhancement (fixed)

thunderbird-78.11.0

Reported by: Bruce Dubbs Owned by: Tim Tassonis
Priority: elevated Milestone: 10.2
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

New minor version.

Change History (5)

comment:1 by Tim Tassonis, 3 weeks ago

Owner: changed from blfs-book to Tim Tassonis
Status: newassigned

Fixes

OpenPGP could not be disabled for an account if a key was previously configured fixed

Recipients were unable to decrypt some messages when the sender had changed the message encryption from OpenPGP to S/MIME fixed

Contacts moved between CardDAV address books were not synced to the new server fixed

CardDAV compatibility fixes for Google Contacts fixed

Folder pane had no clear indication of focus on macOS fixed

Windows theme improvements fixed

comment:2 by Tim Tassonis, 3 weeks ago

Resolution: fixed
Status: assignedclosed

Fixed in commit 3d8d1aa9ea

comment:3 by Tim Tassonis, 3 weeks ago

Resolution: fixed
Status: closedreopened

comment:4 by Tim Tassonis, 2 weeks ago

Resolution: fixed
Status: reopenedclosed

Fixed in commit 2f5b2832c3

comment:5 by Douglas R. Reno, 2 weeks ago

Priority: normalelevated
Mozilla Foundation Security Advisory 2021-26
Security Vulnerabilities fixed in Thunderbird 78.11

Announced
    June 3, 2021
Impact
    moderate
Products
    Thunderbird
Fixed in

        Thunderbird 78.11

#CVE-2021-29964: Out of bounds-read when parsing a `WM_COPYDATA` message

Reporter
    Ronald Crane
Impact
    moderate

Description

A locally-installed hostile program could send WM_COPYDATA messages that Thunderbird would processing incorrectly, leading to an out-of-bounds read.
This bug only affects Thunderbird on Windows. Other operating systems are unaffected.
References

    Bug 1706501

#CVE-2021-29967: Memory safety bugs fixed in Thunderbird 78.11

Reporter
    Mozilla developers and community
Impact
    high

Description

Mozilla developers Gabriele Svelto, Anny Gakhokidze, Alexandru Michis, Christian Holler reported memory safety bugs present in Thunderbird 78.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
References

    Memory safety bugs fixed in Thunderbird 78.11
Note: See TracTickets for help on using tickets.