Package thunderbird: Information

  • Default inline alert: Version in the repository: 115.9.0-alt1

Source package: thunderbird
Version: 102.10.0-alt1
Latest version according to Repology
Build time:  Apr 20, 2023, 10:45 AM in the task #318817
Category: Networking/Mail
Report package bug
License: MPL-2.0
Summary: Thunderbird is Mozilla's e-mail client
Description: 
Thunderbird is Mozilla's next generation e-mail client. Thunderbird makes
emailing safer, faster and easier than ever before and can also scale to meet
the most sophisticated organizational needs.

The package contains Lightning - an integrated calendar for Thunderbird.

List of rpms provided by this srpm:
rpm-build-thunderbird (x86_64, ppc64le, i586, aarch64)
thunderbird (x86_64, ppc64le, i586, aarch64)
thunderbird-wayland (x86_64, ppc64le, i586, aarch64)

Maintainer: Andrey Cherepanov



    1. python3-module-pip
    2. libcairo-devel
    3. python3-module-setuptools
    4. /dev/shm
    5. python3-modules-sqlite3
    6. libcurl-devel
    7. libdav1d-devel
    8. libdbus-devel
    9. libdbus-glib-devel
    10. libshell
    11. gst-plugins1.0-devel
    12. libdrm-devel
    13. gstreamer1.0-devel
    14. /proc
    15. libevent-devel
    16. fontconfig-devel
    17. libffi-devel
    18. libfreetype-devel
    19. libstartup-notification-devel
    20. libstdc++-devel
    21. libX11-devel
    22. libgio-devel
    23. libXScrnSaver-devel
    24. libXcomposite-devel
    25. libXcursor-devel
    26. libXdamage-devel
    27. libXext-devel
    28. rpm-build-mozilla.org
    29. libXft-devel
    30. libXi-devel
    31. libXt-devel
    32. rpm-macros-alternatives
    33. libgtk+2-devel
    34. libgtk+3-devel
    35. alternatives
    36. libalsa-devel
    37. libaom-devel
    38. libhunspell-devel
    39. autoconf_2.13
    40. autoconf_2.13
    41. libjpeg-devel
    42. pkgconfig(alsa)
    43. pkgconfig(aom)
    44. pkgconfig(bzip2)
    45. pkgconfig(cairo)
    46. pkgconfig(dav1d)
    47. pkgconfig(dbus-1)
    48. pkgconfig(dbus-glib-1)
    49. pkgconfig(dri)
    50. pkgconfig(fontconfig)
    51. pkgconfig(freetype2)
    52. pkgconfig(gio-2.0)
    53. pkgconfig(graphite2)
    54. pkgconfig(gtk+-2.0)
    55. pkgconfig(gtk+-3.0)
    56. pkgconfig(harfbuzz)
    57. pkgconfig(hunspell)
    58. pkgconfig(icu-i18n)
    59. pkgconfig(libcurl)
    60. pkgconfig(libdrm)
    61. browser-plugins-npapi-devel
    62. pkgconfig(libevent)
    63. pkgconfig(libffi)
    64. pkgconfig(libjpeg)
    65. bzlib-devel
    66. pkgconfig(libnotify)
    67. pkgconfig(libproxy-1.0)
    68. pkgconfig(libpulse)
    69. pkgconfig(libstartup-notification-1.0)
    70. chrpath
    71. pkgconfig(nspr) >= 4.33
    72. pkgconfig(nss) >= 3.77
    73. pkgconfig(opus)
    74. clang12.0
    75. clang12.0-devel
    76. pkgconfig(pixman-1)
    77. libvpx-devel
    78. python3-base
    79. pkgconfig(vpx)
    80. pkgconfig(x11)
    81. pkgconfig(xcomposite)
    82. pkgconfig(xcursor)
    83. pkgconfig(xdamage)
    84. pkgconfig(xext)
    85. pkgconfig(xft)
    86. pkgconfig(xi)
    87. pkgconfig(xkbcommon)
    88. pkgconfig(xrandr)
    89. pkgconfig(xscrnsaver)
    90. pkgconfig(xt)
    91. pkgconfig(xtst)
    92. pkgconfig(zlib)
    93. libwireless-devel
    94. libxkbcommon-devel
    95. libGL-devel
    96. python-module-setuptools
    97. python-modules-compiler
    98. python-modules-json
    99. python-modules-logging
    100. python-modules-sqlite3
    101. lld12.0-devel
    102. llvm12.0-devel
    103. libnotify-devel
    104. libnss-devel-static
    105. rust >= 1.60.0
    106. rust-cargo >= 1.60.0
    107. mozilla-common-devel
    108. libopus-devel
    109. nasm
    110. node
    111. libpixman-devel
    112. unzip
    113. xorg-cf-files
    114. yasm
    115. libpulseaudio-devel
    116. zip
    117. zlib-devel
    118. libproxy-devel

Last changed


April 19, 2023 Pavel Vasenkov 102.10.0-alt1
- New version.
- Security fixes:
  + CVE-2023-29531 Out-of-bound memory access in WebGL on macOS
  + CVE-2023-29532 Mozilla Maintenance Service Write-lock bypass
  + CVE-2023-29533 Fullscreen notification obscured
  + CVE-2023-1999 Double-free in libwebp
  + CVE-2023-29535 Potential Memory Corruption following Garbage Collector compaction
  + CVE-2023-29536 Invalid free from JavaScript code
  + CVE-2023-0547 Revocation status of S/Mime recipient certificates was not checked
  + CVE-2023-29479 Hang when processing certain OpenPGP messages
  + CVE-2023-29539 Content-Disposition filename truncation leads to Reflected File Download
  + CVE-2023-29541 Files with malicious extensions could have been downloaded unsafely on Linux
  + CVE-2023-29542 Bypass of file download extension restrictions
  + CVE-2023-29545 Windows Save As dialog resolved environment variables
  + CVE-2023-1945 Memory Corruption in Safe Browsing Code
  + CVE-2023-29548 Incorrect optimization result on ARM64
  + CVE-2023-29550 Memory safety bugs fixed in Thunderbird 102.10
March 22, 2023 Pavel Vasenkov 102.9.0-alt1
- New version.
- Security fixes:
  + CVE-2023-25751 Incorrect code generation during JIT compilation
  + CVE-2023-28164 URL being dragged from a removed cross-origin iframe into the same tab triggered navigation
  + CVE-2023-28162 Invalid downcast in Worklets
  + CVE-2023-25752 Potential out-of-bounds when accessing throttled streams
  + CVE-2023-28163 Windows Save As dialog resolved environment variables
  + CVE-2023-28176 Memory safety bugs fixed in Thunderbird 102.9
Feb. 28, 2023 Pavel Vasenkov 102.8.0-alt1
- New version.
- Security fixes:
  + CVE-2023-0616 User Interface lockup with messages combining S/MIME and OpenPGP
  + CVE-2023-25728 Content security policy leak in violation reports using iframes
  + CVE-2023-25730 Screen hijack via browser fullscreen mode
  + CVE-2023-0767 Arbitrary memory write via PKCS 12 in NSS
  + CVE-2023-25735 Potential use-after-free from compartment mismatch in SpiderMonkey
  + CVE-2023-25737 Invalid downcast in SVGUtils::SetupStrokeGeometry
  + CVE-2023-25738 Printing on Windows could potentially crash Thunderbird with some device drivers
  + CVE-2023-25739 Use-after-free in mozilla::dom::ScriptLoadContext::~ScriptLoadContext
  + CVE-2023-25729 Extensions could have opened external schemes without user knowledge
  + CVE-2023-25732 Out of bounds memory write from EncodeInputStream
  + CVE-2023-25734 Opening local .url files could cause unexpected network loads
  + CVE-2023-25742 Web Crypto ImportKey crashes tab
  + CVE-2023-25746 Memory safety bugs fixed in Thunderbird 102.8