Package thunderbird: Information

Source package: thunderbird
Version: 60.7.1-alt2
Build time:  Jun 19, 2019, 02:11 PM in the task #232570
Category: Networking/Mail
Report package bug
License: MPL/GPL
Summary: Thunderbird is Mozilla's e-mail client
Description: 
Thunderbird is Mozilla's next generation e-mail client.
Thunderbird makes emailing safer, faster and easier than
ever before and can also scale to meet the most sophisticated
organizational needs.
The package contains Lightning - an integrated calendar for Thunderbird.

List of rpms provided by this srpm:
rpm-build-thunderbird (noarch)
thunderbird (x86_64, i586, aarch64)
thunderbird-enigmail (x86_64, i586, aarch64)

Maintainer: Andrey Cherepanov


    1. libstartup-notification-devel
    2. libstdc++-devel
    3. /proc
    4. libgio-devel
    5. lld-devel
    6. gst-plugins1.0-devel
    7. gstreamer1.0-devel
    8. llvm7.0-devel
    9. doxygen
    10. makedepend
    11. libnotify-devel
    12. libnspr-devel
    13. libnss-devel
    14. libnss-devel-static
    15. libGL-devel
    16. libIDL-devel
    17. fontconfig-devel
    18. mozilla-common-devel
    19. mozldap-devel
    20. libopus-devel
    21. rust
    22. libgtk+2-devel
    23. rust-cargo
    24. libgtk+3-devel
    25. imake
    26. gcc-c++
    27. libhunspell-devel
    28. libX11-devel
    29. libpixman-devel
    30. libjpeg-devel
    31. libcairo-devel
    32. libXScrnSaver-devel
    33. python-module-distribute
    34. rpm-build-mozilla.org
    35. libXcomposite-devel
    36. libXcursor-devel
    37. libXdamage-devel
    38. libXext-devel
    39. alternatives
    40. libXft-devel
    41. libXi-devel
    42. python-modules-compiler
    43. libproxy-devel
    44. python-modules-json
    45. python-modules-logging
    46. python-modules-sqlite3
    47. libcurl-devel
    48. autoconf_2.13
    49. libXt-devel
    50. autoconf_2.13
    51. unzip
    52. libdbus-glib-devel
    53. libalsa-devel
    54. libpulseaudio-devel
    55. browser-plugins-npapi-devel
    56. xorg-cf-files
    57. bzlib-devel
    58. yasm
    59. libevent-devel
    60. chrpath
    61. zip
    62. zlib-devel
    63. clang7.0
    64. clang7.0-devel
    65. libffi-devel
    66. libfreetype-devel
    67. libvpx5-devel
    68. libwireless-devel

Last changed


June 18, 2019 Andrey Cherepanov 60.7.1-alt2
- enigmail: disable pEpAutoDownload.
June 14, 2019 Andrey Cherepanov 60.7.1-alt1
- New version (60.7.1).
- Fixed:
  + CVE-2019-11703 Heap buffer overflow in icalparser.c
  + CVE-2019-11704 Heap buffer overflow in icalvalue.c
  + CVE-2019-11705 Stack buffer overflow in icalrecur.c
  + CVE-2019-11706 Type confusion in icalproperty.c
- Enigmail 2.0.11.
- thunderbird-enigmail now requires pinentry-x11 (ALT #18790).
- Use juniorModeForceOff by default in Enigmail (ALT #36447).
- Fix l10n dtd of Enigmail.
May 20, 2019 Andrey Cherepanov 60.7.0-alt1
- New version (60.7.0).
- Fixed:
  + CVE-2019-9815 Disable hyperthreading on content JavaScript threads on macOS
  + CVE-2019-9816 Type confusion with object groups and UnboxedObjects
  + CVE-2019-9817 Stealing of cross-domain images using canvas
  + CVE-2019-9818 Use-after-free in crash generation server
  + CVE-2019-9819 Compartment mismatch with fetch API
  + CVE-2019-9820 Use-after-free of ChromeEventHandler by DocShell
  + CVE-2019-11691 Use-after-free in XMLHttpRequest
  + CVE-2019-11692 Use-after-free removing listeners in the event listener manager
  + CVE-2019-11693 Buffer overflow in WebGL bufferdata on Linux
  + CVE-2019-7317 Use-after-free in png_image_free of libpng library
  + CVE-2019-9797 Cross-origin theft of images with createImageBitmap
  + CVE-2018-18511 Cross-origin theft of images with ImageBitmapRenderingContext
  + CVE-2019-11694 Uninitialized memory memory leakage in Windows sandbox
  + CVE-2019-11698 Theft of user history data through drag and drop of hyperlinks to and from bookmarks
  + CVE-2019-5798 Out-of-bounds read in Skia
  + CVE-2019-9800 Memory safety bugs fixed in Firefox 67, Firefox ESR 60.7, and Thunderbird 60.7