Opened 8 months ago

Closed 7 months ago

#22825 closed enhancement (fixed)

thunderbird-140.8.0

Reported by: Douglas R. Reno Owned by: zeckma
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: critical Keywords:
Cc:

Description

New point version

Change History (10)

comment:1 by Douglas R. Reno, 8 months ago

Milestone: 13.1 → 13.0

Neither of these packages are tagged yet, so let's move them to 13.0

comment:2 by zeckma, 8 months ago

Owner: changed from blfs-book to zeckma
Status: new → assigned

comment:3 by zeckma, 7 months ago

Fixes CVE-2026-2447 for bundled libvpx. More information can be found here: https://wiki.linuxfromscratch.org/blfs/ticket/22827.

comment:4 by zeckma, 7 months ago

Priority: normal → high

comment:5 by zeckma, 7 months ago

Fixed at ee5e75b46f7619b0979de2b16d190bf039c1eaaf. Leaving open for SA.

comment:6 by Douglas R. Reno, 7 months ago

Severity: normal → critical
Summary: thunderbird-140.7.2 → thunderbird-140.8.0

Same 37 CVEs as Firefox.

comment:7 by Joe Locash, 7 months ago

Who ever packaged the release screwed up. Some of the rust cargo-checksum files have .gitmodules in them. Here's a sed that will take care of that:

sed -e 's|,"[^"]*.gitmodules[^,]*[^,]||' -e '$a\' -i comm/third_party/rust/{minimal-lexical,lmdb-rkv,cubeb-sys,wasi,glslopt,sfv}/.cargo-checksum.json

comment:8 by zeckma, 7 months ago

I determined that Firefox won't need that command, but Thunderbird will.

comment:9 by zeckma, 7 months ago

Fixed at 15d707cc92c2fdc3fa686def01d5fe778dae0be9. Leaving open for an SA... or a new Thunderbird version, which I hope not.

comment:10 by zeckma, 7 months ago

Resolution: → fixed
Status: assigned → closed

SA-12.4-102 issued.

Note: See TracTickets for help on using tickets.