[DSA 6418-1] thunderbird security update

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6418-1                   [email protected]
https://www.debian.org/security/                     Salvatore Bonaccorso
August 07, 2026                       https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : thunderbird
CVE ID         : CVE-2026-14899 CVE-2026-15718 CVE-2026-15719 CVE-2026-16349
                 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353
                 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357
                 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16361
                 CVE-2026-16362 CVE-2026-16363 CVE-2026-16368 CVE-2026-16369
                 CVE-2026-16371 CVE-2026-16374 CVE-2026-16375 CVE-2026-16377
                 CVE-2026-16379 CVE-2026-16381 CVE-2026-16383 CVE-2026-16387
                 CVE-2026-16390 CVE-2026-16391 CVE-2026-16396 CVE-2026-16405
                 CVE-2026-16412 CVE-2026-57962 CVE-2026-57963

Multiple security issues were discovered in Thunderbird, which could
result in the execution of arbitrary code.

For the stable distribution (trixie), these problems have been fixed in
version 1:140.13.0esr-2~deb13u1.

We recommend that you upgrade your thunderbird packages.

For the detailed security status of thunderbird please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/thunderbird

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmp2L4VfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0Tr0A/9EfjCfnKHXqC4Q2yV0ih+4eajdCv0/zK+lgAN66ecNTdtWr4XZmG9xU5e
PMWxiLKabzAGJBVd1Y8KvR6NBJQOQJFZsALWdLG4+Ov0fOwIOWwQ9SBqiKx1Y3XG
BNKNVVcUigbAld4BOnUezWAGKwIJl59mwKCNJhu+RukWeynx9B1hanjh3Hn8Yh7I
spbMZ7dFnkfpCZgTSUxRgBv3o9ZgJqznBntKieZY/bxLX+L2WCaTc3nkK6PeT7YK
XKCjPlyDrqW5bMBa5oeJl123hQktMEZBb8zSiE0fgUuMXEkkwYUshdK0n2uFYRxC
MIiUEEQpFEDlvazc7bsWuPXyuoySvrbvkOt14QJ4/p+KzD4XbHbKGT7BktnmXalv
ksQV6U3kFO95Kho9DaAKBEI5UFBGOQ0eXg+b8sQPe+N+ZiYiPvH6BibhabG0m8oJ
c+EP0Mmvogs5t2RVCy0gnz7Z9RJVWHyjt1xKZJSeXLwKchNGY59Gc/qTOv4bpicV
MdqkyJeeat8eLqssKEP2N2rEqX1v+vLBWDGfqa672s1V1f/czppWYz0RiDYCI26I
vx+A4/da2bJdMtUnczOPI7uEwMQuX4pnPjfOFXEjWo5JfTjjqfWZhGqqAOLqMh2o
VHvCACRMJmW93QlsFxgbXvd9527JLxTNqhQB3/uAW7IwaVVIDLw=
=AsH0
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.