--- - branch: MAIN date: Tue Nov 21 21:32:51 UTC 2023 files: - new: '1.305' old: '1.304' path: pkgsrc/mail/thunderbird/Makefile pathrev: pkgsrc/mail/thunderbird/Makefile@1.305 type: modified - new: '1.92' old: '1.91' path: pkgsrc/mail/thunderbird/PLIST pathrev: pkgsrc/mail/thunderbird/PLIST@1.92 type: modified - new: '1.260' old: '1.259' path: pkgsrc/mail/thunderbird/distinfo pathrev: pkgsrc/mail/thunderbird/distinfo@1.260 type: modified - new: '1.11' old: '1.10' path: pkgsrc/mail/thunderbird/mozilla-common.mk pathrev: pkgsrc/mail/thunderbird/mozilla-common.mk@1.11 type: modified - new: '0' old: '1.1' path: pkgsrc/mail/thunderbird/patches/patch-intl_lwbrk_LineBreaker.cpp pathrev: pkgsrc/mail/thunderbird/patches/patch-intl_lwbrk_LineBreaker.cpp@0 type: deleted id: 20231121T213251Z.b3caa179b23048b251012d255a1f969053c57b6f log: | thunderbird: Update to 115.4.3 * Use internal icu to fix the runtime errors in calendar. Changelog: 115.4.3: Fixes fixed Forwarding multiple messages as attachments failed fixed Message list scrolling fixes fixed Some text remained incorrectly visible in the message list when using "Grouped By" sorting fixed Subject lines were excessively indented in "Grouped by" views fixed "Open Message in Conversation" was incorrectly enabled for selections of multiple messages fixed States of collapsed and expanded threads were not maintained when switching folders fixed Pressing "n" to move to the next unread message on an unread, collapsed thread opened the thread and selected the second message instead of the first fixed Search Folders dialog improvements fixed "Read Messages" button in Account Central did not retrieve mail from POP accounts fixed Events canceled by the organizer were incorrectly sent cancelation message 115.4.2: Fixes fixed No messages or calendar items were displayed on startup fixed Toolbar & Folder View widget fixes fixed Insert image dialog was not properly sized on some localized builds fixed The "unencrypted subject" icon was always briefly displayed when replying to a message fixed RSS feeds with lengthy attachment filenames cut off visible content fixed RSS feeds with no favicon displayed default icon in the folder color fixed NNTP messages that were previously downloaded were not displayed if the server went offline fixed Vcard photos were not imported when using opening the file with Thunderbird fixed Publishing calendars to invalid URLs did not display a helpful error fixed Publishing calendar events via authenticated WebDAV failed fixed Converting a message to an event failed when the message pane was not displayed fixed Redirect dialog displayed for WebDAV calendars was too small fixed Visual and Theme improvements 115.4.1: What's New new "Manage Newsgroups Subscription" now displayed on Account Central when using newsgroups Fixes fixed Manually configured authentication methods on accounts did not always persist fixed "Send Autocrypt key in header" preference was available on accounts with no encryption key fixed SHA-1 certificates were not accepted in Thunderbird 115; acceptance of SHA-1 messages can now be enabled via optional preference fixed Various Flatpak enhancements fixed Opening folder in new tab by clicking scroll wheel/middle mouse button did not work in Folder Pane fixed Message list did not automatically scroll to new messages when switching folders fixed "Move/Copy to again" was sometimes displayed in the folder context menu when it should not have been fixed Multiple message drafts or message templates could not be opened simultaneously for editing fixed Tools > Filters dialog did not open in Unified Folder view if no messages were selected fixed Printing dialog could be opened, even with no messages selected fixed "From" address was editable when creating a new message from a template if the account identity contained Unicode characters fixed Opening a saved .eml file in compose window did not preserve message subject from file fixed Replying to some plaintext messages with desired quote selected in original message did not preserve formatting of quote fixed "Edit as New", "Reply", and "Redirect" could not be used on multiple messages simultaneously fixed "Reply to List" option was always enabled, even with no list to reply to fixed "Archive" button in message pane was enabled on messages that could not be archived fixed "Followup-To" label was incorrectly labeled as "Newsgroups" fixed "Save image as" option did not work for RSS feed items displayed as a webpage fixed OTR verification dialog was blank, preventing verification of OTR chat sessions fixed Calendar event import failed for some ICS files fixed Permission description strings were missing from Add-Ons Manager fixed Various visual fixes fixed Security fixes Security fixes: Mozilla Foundation Security Advisory 2023-47 #CVE-2023-5721: Queued up rendering could have allowed websites to clickjack #CVE-2023-5732: Address bar spoofing via bidirectional characters #CVE-2023-5724: Large WebGL draw could have led to a crash #CVE-2023-5725: WebExtensions could open arbitrary URLs #CVE-2023-5726: Full screen notification obscured by file open dialog on macOS #CVE-2023-5727: Download Protections were bypassed by .msix, .msixbundle, .appx, and .appxbundle files on Windows #CVE-2023-5728: Improper object tracking during GC in the JavaScript engine could have led to a crash. #CVE-2023-5730: Memory safety bugs fixed in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4.1 115.3.3: Fixes fixed Modifier keys did not work as expected when dragging a message over the folder tree on macOS fixed "Folder Location" toolbar button did not work for local folders fixed "Copy to again" option disappeared from context menu after copying to Gmail folder with non-ASCII name fixed Default reply identity did not use "Delivered-To" address when catch-all was active fixed "View Headers All" did not work when selected in standalone message window fixed Viewing the mail filter log displayed an error if no log file was present 115.3.2: Fixes fixed "Open in conversation" did not open messages in a thread view fixed News messsage with non-ASCII author name were incorrectly canceled fixed Localized "Re: " prefix was not stripped from news messages fixed Thunderbird attempted to load accounts missing server hostname, causing blank 3-pane window fixed Permission description strings were missing from Add-Ons Manager fixed Card View displayed incorrect recipient name for mail and news accounts, depending on folder fixed Spell check dictionary dialog sometimes pushed Close button out of view fixed Importing calendars from iCal files did not work under certain circumstances fixed Calendar invitations were not sent to event participants, only organizer fixed Calendar alarm dialogs with lengthy descriptions pushed buttons out of view fixed Various visual fixes 115.3.1: Fixes fixed In Unified Folders view, some folders had incorrect unified folder parent fixed "Edit message as new" did not restore encrypted subject from selected message fixed Importing some CalDAV calendars with yearly recurrence events caused Thunderbird to freeze fixed Security fixes Mozilla Foundation Security Advisory 2023-44 #CVE-2023-5217: Heap buffer overflow in libvpx 115.3.0: Fixes fixed Thunderbird could not import profiles with hostname ending in dot (".") fixed Message header was occasionally missing in message preview fixed Setting an existing folder's type flag did not add descendant folders to the Unified Folders view fixed Thunderbird did not always delete all temporary mail files, sometimes preventing messages from being sent fixed Status bar in Message Compose window could not be hidden fixed Message header was intermittently missing from message preview fixed OAuth2 did not work on some profiles created in Thunderbird 102.6.1 or earlier fixed In Vertical View, decrypted subject lines were displayed as ellipsis ("...") in message list fixed Condensed address preference (mail.showCondensedAddresses) did not show condensed addresses in message list fixed Spam folder could not be assigned non-ASCII names with IMAP UTF-8 enabled fixed Message header was not displayed until images finished loading, causing noticeable delay for messages containing large images fixed Large SVG favicons did not display on RSS feeds fixed Context menu items did not display a hover background color fixed Security fixes Mozilla Foundation Security Advisory 2023-43 #CVE-2023-5168: Out-of-bounds write in FilterNodeD2D1 #CVE-2023-5169: Out-of-bounds write in PathOps #CVE-2023-5171: Use-after-free in Ion Compiler #CVE-2023-5174: Double-free in process spawning on Windows #CVE-2023-5176: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3 115.2.3: Changes changed Card view and vertical layout are now default for new profiles Fixes fixed Go > Folder menu was disabled fixed "Tools" menu was blank when opened from compose window on macOS fixed Deleting an attachment from a message on an IMAP server corrupted the local copy when configured with "mark as deleted" fixed Manually entered passwords were not remembered for OAuth-authenticated accounts such as Yahoo mail fixed Quick Filter's "Keep filters applied" did not persist after restarting Thunderbird fixed Top-level Quick Filter settings did not persist after restart fixed Notifications for new messages with non-ASCII characters in the subject were garbled fixed "Mark Thread As Read" did not work when some messages in thread were already read fixed New Groups tab in NNTP subscribe dialog id not work as expected fixed Negative values were allowed in "Share for files larger than" field fixed Thunderbird sometimes crashed when deleting a parent folder with subfolders fixed "Send Message Error" appeared intermittently while Thunderbird was idle fixed Focused but not selected messages were missing visual indication of focus in card view fixed Notification dot did not disappear from taskbar icon on Windows after messages had already been read fixed Multiple selected messages could not be opened simultaneously if selection included more than 19 messages fixed Email replies received via BCC incorrectly populated From field with default identity fixed User was not always notified of message send failures in outbox fixed Tag dialog did not close properly after editing tag fixed Newsgroup field in compose window did not autocomplete with suggested newsgroup names fixed Canceling newsgroup messages did not check if sender matched user's own identity fixed Event dialog with several invitees expanded beyond screen height fixed Message check boxes were partially obstructed in message list 115.4.3: Fixes fixed Forwarding multiple messages as attachments failed fixed Message list scrolling fixes fixed Some text remained incorrectly visible in the message list when using "Grouped By" sorting fixed Subject lines were excessively indented in "Grouped by" views fixed "Open Message in Conversation" was incorrectly enabled for selections of multiple messages fixed States of collapsed and expanded threads were not maintained when switching folders fixed Pressing "n" to move to the next unread message on an unread, collapsed thread opened the thread and selected the second message instead of the first fixed Search Folders dialog improvements fixed "Read Messages" button in Account Central did not retrieve mail from POP accounts fixed Events canceled by the organizer were incorrectly sent cancelation message 115.4.2: Fixes fixed No messages or calendar items were displayed on startup fixed Toolbar & Folder View widget fixes fixed Insert image dialog was not properly sized on some localized builds fixed The "unencrypted subject" icon was always briefly displayed when replying to a message fixed RSS feeds with lengthy attachment filenames cut off visible content fixed RSS feeds with no favicon displayed default icon in the folder color fixed NNTP messages that were previously downloaded were not displayed if the server went offline fixed Vcard photos were not imported when using opening the file with Thunderbird fixed Publishing calendars to invalid URLs did not display a helpful error fixed Publishing calendar events via authenticated WebDAV failed fixed Converting a message to an event failed when the message pane was not displayed fixed Redirect dialog displayed for WebDAV calendars was too small fixed Visual and Theme improvements 115.4.1: What's New new "Manage Newsgroups Subscription" now displayed on Account Central when using newsgroups Fixes fixed Manually configured authentication methods on accounts did not always persist fixed "Send Autocrypt key in header" preference was available on accounts with no encryption key fixed SHA-1 certificates were not accepted in Thunderbird 115; acceptance of SHA-1 messages can now be enabled via optional preference fixed Various Flatpak enhancements fixed Opening folder in new tab by clicking scroll wheel/middle mouse button did not work in Folder Pane fixed Message list did not automatically scroll to new messages when switching folders fixed "Move/Copy to again" was sometimes displayed in the folder context menu when it should not have been fixed Multiple message drafts or message templates could not be opened simultaneously for editing fixed Tools > Filters dialog did not open in Unified Folder view if no messages were selected fixed Printing dialog could be opened, even with no messages selected fixed "From" address was editable when creating a new message from a template if the account identity contained Unicode characters fixed Opening a saved .eml file in compose window did not preserve message subject from file fixed Replying to some plaintext messages with desired quote selected in original message did not preserve formatting of quote fixed "Edit as New", "Reply", and "Redirect" could not be used on multiple messages simultaneously fixed "Reply to List" option was always enabled, even with no list to reply to fixed "Archive" button in message pane was enabled on messages that could not be archived fixed "Followup-To" label was incorrectly labeled as "Newsgroups" fixed "Save image as" option did not work for RSS feed items displayed as a webpage fixed OTR verification dialog was blank, preventing verification of OTR chat sessions fixed Calendar event import failed for some ICS files fixed Permission description strings were missing from Add-Ons Manager fixed Various visual fixes fixed Security fixes Security fixes: Mozilla Foundation Security Advisory 2023-47 #CVE-2023-5721: Queued up rendering could have allowed websites to clickjack #CVE-2023-5732: Address bar spoofing via bidirectional characters #CVE-2023-5724: Large WebGL draw could have led to a crash #CVE-2023-5725: WebExtensions could open arbitrary URLs #CVE-2023-5726: Full screen notification obscured by file open dialog on macOS #CVE-2023-5727: Download Protections were bypassed by .msix, .msixbundle, .appx, and .appxbundle files on Windows #CVE-2023-5728: Improper object tracking during GC in the JavaScript engine could have led to a crash. #CVE-2023-5730: Memory safety bugs fixed in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4.1 115.3.3: Fixes fixed Modifier keys did not work as expected when dragging a message over the folder tree on macOS fixed "Folder Location" toolbar button did not work for local folders fixed "Copy to again" option disappeared from context menu after copying to Gmail folder with non-ASCII name fixed Default reply identity did not use "Delivered-To" address when catch-all was active fixed "View Headers All" did not work when selected in standalone message window fixed Viewing the mail filter log displayed an error if no log file was present 115.3.2: Fixes fixed "Open in conversation" did not open messages in a thread view fixed News messsage with non-ASCII author name were incorrectly canceled fixed Localized "Re: " prefix was not stripped from news messages fixed Thunderbird attempted to load accounts missing server hostname, causing blank 3-pane window fixed Permission description strings were missing from Add-Ons Manager fixed Card View displayed incorrect recipient name for mail and news accounts, depending on folder fixed Spell check dictionary dialog sometimes pushed Close button out of view fixed Importing calendars from iCal files did not work under certain circumstances fixed Calendar invitations were not sent to event participants, only organizer fixed Calendar alarm dialogs with lengthy descriptions pushed buttons out of view fixed Various visual fixes 115.3.1: Fixes fixed In Unified Folders view, some folders had incorrect unified folder parent fixed "Edit message as new" did not restore encrypted subject from selected message fixed Importing some CalDAV calendars with yearly recurrence events caused Thunderbird to freeze fixed Security fixes Mozilla Foundation Security Advisory 2023-44 #CVE-2023-5217: Heap buffer overflow in libvpx 115.3.0: Fixes fixed Thunderbird could not import profiles with hostname ending in dot (".") fixed Message header was occasionally missing in message preview fixed Setting an existing folder's type flag did not add descendant folders to the Unified Folders view fixed Thunderbird did not always delete all temporary mail files, sometimes preventing messages from being sent fixed Status bar in Message Compose window could not be hidden fixed Message header was intermittently missing from message preview fixed OAuth2 did not work on some profiles created in Thunderbird 102.6.1 or earlier fixed In Vertical View, decrypted subject lines were displayed as ellipsis ("...") in message list fixed Condensed address preference (mail.showCondensedAddresses) did not show condensed addresses in message list fixed Spam folder could not be assigned non-ASCII names with IMAP UTF-8 enabled fixed Message header was not displayed until images finished loading, causing noticeable delay for messages containing large images fixed Large SVG favicons did not display on RSS feeds fixed Context menu items did not display a hover background color fixed Security fixes Mozilla Foundation Security Advisory 2023-43 #CVE-2023-5168: Out-of-bounds write in FilterNodeD2D1 #CVE-2023-5169: Out-of-bounds write in PathOps #CVE-2023-5171: Use-after-free in Ion Compiler #CVE-2023-5174: Double-free in process spawning on Windows #CVE-2023-5176: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3 115.2.3: Changes changed Card view and vertical layout are now default for new profiles Fixes fixed Go > Folder menu was disabled fixed "Tools" menu was blank when opened from compose window on macOS fixed Deleting an attachment from a message on an IMAP server corrupted the local copy when configured with "mark as deleted" fixed Manually entered passwords were not remembered for OAuth-authenticated accounts such as Yahoo mail fixed Quick Filter's "Keep filters applied" did not persist after restarting Thunderbird fixed Top-level Quick Filter settings did not persist after restart fixed Notifications for new messages with non-ASCII characters in the subject were garbled fixed "Mark Thread As Read" did not work when some messages in thread were already read fixed New Groups tab in NNTP subscribe dialog id not work as expected fixed Negative values were allowed in "Share for files larger than" field fixed Thunderbird sometimes crashed when deleting a parent folder with subfolders fixed "Send Message Error" appeared intermittently while Thunderbird was idle fixed Focused but not selected messages were missing visual indication of focus in card view fixed Notification dot did not disappear from taskbar icon on Windows after messages had already been read fixed Multiple selected messages could not be opened simultaneously if selection included more than 19 messages fixed Email replies received via BCC incorrectly populated From field with default identity fixed User was not always notified of message send failures in outbox fixed Tag dialog did not close properly after editing tag fixed Newsgroup field in compose window did not autocomplete with suggested newsgroup names fixed Canceling newsgroup messages did not check if sender matched user's own identity fixed Event dialog with several invitees expanded beyond screen height fixed Message check boxes were partially obstructed in message list 115.2.0: What's New new Thunderbird MSIX packages are now published on archive.mozilla.org Changes changed Size, Unread, and Total columns are now right-aligned changed Newsgroup names in message list header are now abbreviated Fixes fixed Message compose window did not apply theme colors to menus fixed Reading the second new message in a folder cleared the unread indicator of all other new messages fixed Displayed counts of unread or flagged messages could become out-of-sync fixed Deleting a message from the context menu with messages sorted in chronological order and smooth scroll enabled caused message list to scroll to top fixed Repeatedly switching accounts in Subscribe dialog caused tree view to stop updating fixed "Ignore thread" caused message cards to display incorrectly in message list fixed Creating tags from unified toolbar failed fixed Cross-folder navigation using F and N did not work fixed Account Manager did not resize to fit content, causing "Close" button to become hidden outside bounds of dialog when too many accounts were listed fixed Remote content exceptions could not be added in Settings fixed Newsgroup list file did not get updated after adding a new NNTP server fixed "Download all headers" option in NNTP "Download Headers" dialog was incorrectly selected by default fixed "Convert to event/task" was missing from mail context menu fixed Events and tasks were not shown in some cases despite being present on remote server fixed Various visual and UX improvements fixed Security fixes Mozilla Foundation Security Advisory 2023-38 #CVE-2023-4573: Memory corruption in IPC CanvasTranslator #CVE-2023-4574: Memory corruption in IPC ColorPickerShownCallback #CVE-2023-4575: Memory corruption in IPC FilePickerShownCallback #CVE-2023-4576: Integer Overflow in RecordedSourceSurfaceCreation #CVE-2023-4577: Memory corruption in JIT UpdateRegExpStatics #CVE-2023-4051: Full screen notification obscured by file open dialog #CVE-2023-4578: Error reporting methods in SpiderMonkey could have triggered an Out of Memory Exception #CVE-2023-4053: Full screen notification obscured by external program #CVE-2023-4580: Push notifications saved to disk unencrypted #CVE-2023-4581: XLL file extensions were downloadable without warnings #CVE-2023-4582: Buffer Overflow in WebGL glGetProgramiv #CVE-2023-4583: Browsing Context potentially not cleared when closing Private Window #CVE-2023-4584: Memory safety bugs fixed in Firefox 117, Firefox ESR 102.15, Firefox ESR 115.2, Thunderbird 102.15, and Thunderbird 115.2 #CVE-2023-4585: Memory safety bugs fixed in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2 module: pkgsrc subject: 'CVS commit: pkgsrc/mail/thunderbird' unixtime: '1700602371' user: ryoon