[DSA 6461-1] thunderbird security update

Moritz Muehlenhoff <[email protected]>
Newsgroups gmane.linux.debian.user.security.announce
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6461-1                   [email protected]
https://www.debian.org/security/                       Moritz Muehlenhoff
August 23, 2026                       https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : thunderbird
CVE ID         : CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74939 
                 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 
                 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74948 
                 CVE-2026-74949 CVE-2026-74953 CVE-2026-74957 CVE-2026-74959 
                 CVE-2026-74960 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 
                 CVE-2026-74965 CVE-2026-74967 CVE-2026-74969 CVE-2026-74971 
                 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 
                 CVE-2026-74983 CVE-2026-74987 CVE-2026-74990

Multiple security issues were discovered in Thunderbird, which could
result in the execution of arbitrary code or information disclosure

For the stable distribution (trixie), these problems have been fixed in
version 1:140.14.0esr-1~deb13u1.

We recommend that you upgrade your thunderbird packages.

For the detailed security status of thunderbird please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/thunderbird

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmqLHL4ACgkQEMKTtsN8
Tjb2Ag/+OVzBJIPaHckTR3YKCJK4sW7vm07Ixv6yCZ7mqPolTgBI8BwmzQnGXLnN
RtZBOwEBxs/bEqIdvu3djtsIonPAfbGujdTqHGLv5rJW45xBoe3HE859xLD74Uh/
mZz0RTcwx7TH88OWnV99nmeLLlkK7EB/SIUpIAAstQgUfkAppacuIqlYHrJbj86B
yOLb/N7Y484z2Ai6NHpvqqSsFqWsAMQga9k4tcBxEe5jr/PfYDzwECh5RvFGzwDS
SILcmmNQOa1EiJlu70epgP/+hC+syq3Hwv4EIo4WHwBRwA8bITBg5R2YoDQ4KDRq
aGEJB3Z0+7wkpJzzSffU1bowJgauS83Qyg+Rhobj5cU0xPRli3Q0HTvvc8R1D0MN
S9KQeyJoZI0uDp3MyddVVrj/7nd2NicHkGHXmtjmMZLPfDvSGQn3o3O9W0jUUwfa
hoEJKFGGUBVMqfOMJEdi1KKit4+ydZVS3BxLnsW4YYwQG7w7DY54Vyv/q5vGGG80
2uMYsNFoJMaG85y3wsyLSxhGA7nw8DvfcWtQPlxWlRd4BgZd9q/8itpBX4pcv/ED
ny9kur05A7mF2VQREQtWbkPlZbf2wYrHnbXZMY/x3bezgk/JgYHb2Eob6CcANx6Y
w3Jc1mmOxqY9DnVnfDfkpgIR+ZcodPMCRGw0B1ugt3ciy8xdxI8=
=BkHL
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.