Debian alert DLA-4727-1 (thunderbird)
| From: | Emilio Pozuelo Monfort <pochu@debian.org> | |
| To: | <debian-lts-announce@lists.debian.org> | |
| Subject: | [SECURITY] [DLA 4727-1] thunderbird security update | |
| Date: | Mon, 10 Aug 2026 09:56:27 +0200 | |
| Message-ID: | <20260810075627.7A1205F0A4F9@kamino> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4727-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Emilio Pozuelo Monfort August 10, 2026 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : thunderbird Version : 1:140.13.0esr-2~deb11u1 1:140.13.0esr-2~deb12u1 CVE ID : CVE-2026-14899 CVE-2026-15718 CVE-2026-15719 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16361 CVE-2026-16362 CVE-2026-16363 CVE-2026-16368 CVE-2026-16369 CVE-2026-16371 CVE-2026-16374 CVE-2026-16375 CVE-2026-16377 CVE-2026-16379 CVE-2026-16381 CVE-2026-16383 CVE-2026-16387 CVE-2026-16390 CVE-2026-16391 CVE-2026-16396 CVE-2026-16405 CVE-2026-16412 CVE-2026-57962 CVE-2026-57963 Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 1:140.13.0esr-2~deb11u1. For Debian 12 bookworm, these problems have been fixed in version 1:140.13.0esr-2~deb12u1. We recommend that you upgrade your thunderbird packages. For the detailed security status of thunderbird please refer to its security tracker page at: https://security-tracker.debian.org/tracker/thunderbird Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAmp5hCgACgkQnUbEiOQ2 gwKtmw/+OpTxC1HGtKrI7hlIvH4Hto1gM0JwrV8noQPzs3vHlJTjEhy/P7js37lP T+kcq1LVhVZq8jPzm0FRFvUZu6PzKg4FS8JE1Bb77E6xEnhsIhVJ57fUoQQzjh7A pXWuHhXuOuaYoiJ51QW9SXNIfTLI3l0kUFrvNi9DbynMnl2svlMrnV6akkn6MBCh h8T8FOVi8KvWh1oSGXyBS6PsPh4BuL+Nn8wPcurRy5DVgwkMjD5zIHXiorhkSj6i zWVSw//8BJgGfQIct3ymaDZMPNwAS6sw6nEghZlKgtKF2bKpvN/z3FeH0eQwS9+x ZOjp0J99xXqhx6fGGTP6EtvrTtTFCWzfpjIYqidTuXY7jVRd+FsyohG/jcrfp1j+ eWdmt8dUyEKLLy9R8uJBIAelJIxQy2NsYBK1rMxJEw8LpPxIH/Fz4d8+8wBjJqlS 3qri7B0TZTeNvscNsDFHm0YoZOPDlCZEsrFH3DDPikQoDn3YGSV4gaGhCG9iAViv frRTRNtunLHXFQHCGbI74h4hrqsnOzSn0sq8vLpZQBhkq/nQ9uJBkVAyBD2PKdTo 4eampAuwZKxeGmYW/1dQ1rLwziqcoX3diUoq9bCT4hzzVbBE33cCH4Ji8fuid54N wTok45n6RmsemByjO0tGbI+hOQ+8NfFozpncXiseLadxz2FRLsg= =4sAK -----END PGP SIGNATURE-----
