#949649 thunderbird: Please make a separate package for the thunderbird apparmor profile

Package:
thunderbird
Source:
thunderbird
Description:
mail/news client with RSS, chat and integrated spam filter support
Submitter:
Mikhail Morfikov
Date:
2026-09-02 18:21:08 UTC
Severity:
wishlist
#949649#5
Date:
2020-01-23 08:14:27 UTC
From:
To:
Dear Maintainer,

Currently when the thunderbird package is installed, it also installs the
apparmor profile under /etc/apparmor.d/usr.bin.thunderbird . There are two
issues with this:
1) some people want to use their own profile (a local profile, the one under
local/usr.bin.thunderbird isn't an option),
2) the name of this file is "usr.bin.thunderbird" and some users use just
"thunderbird", which leads to having two different sets of rules (two different
files).

The only way to fix this is to manually remove the "usr.bin.thunderbird"
file after each thunderbird update, which is a little bit annoying.

Please reconsider creating a separate package for the apparmor profile (for
instance thunderbird-apparmor-profile), so the user could decide whether he
wants the profile to be installed in his system or not. Thanks.
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQR1ZhNYxftXAnkWpwEy2ctjR5bMoQUCXilV3gAKCRAy2ctjR5bM
oW9WAQCrDxTZWfml6vLW+u655+6WZ9oFjdxKJ7BLla9yHmu6wwD+I0u42UcOX4HB
UabZ6mtFjTxnT4XUBm87+8hWpaERwg4=
=dro9
-----END PGP SIGNATURE-----

#949649#14
Date:
2026-06-22 20:43:26 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
thunderbird, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 949649@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Carsten Schoenert <c.schoenert@t-online.de> (supplier of updated thunderbird package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 22 Jun 2026 21:41:06 +0200
Source: thunderbird
Architecture: source
Version: 1:152.0-1
Distribution: experimental
Urgency: medium
Maintainer: Carsten Schoenert <c.schoenert@t-online.de>
Changed-By: Carsten Schoenert <c.schoenert@t-online.de>
Closes: 880424 882218 883245 900210 909281 914403 917613 928178 949450 949649 955380 961269 1127710 1128672 1128876 1138513
Changes:
 thunderbird (1:152.0-1) experimental; urgency=medium
 .
   [ Carsten Schoenert ]
   * [5097e09] d/control: Bump B-D for libnss3-dev
   * [5350030] New upstream version 152.0
     (Closes: #1138513)
   * [92962df] Rebuild patch queue from patch-queue branch
     Removed patch (included upstream):
     fixes/Fix-conflicting-types-for-once_flag-and-call_once-with-gl.patch
     fixes/Fix-math_private.h-for-i386-FTBFS.patch
     fixes/Fix-sandbox-to-build-with-glibc-2.43.patch
   * [46de392] d/mozconfig.default: Remove option --enable-av1
 .
   [ Christoph Goehre ]
   * [5308430] rebuild patch queue from patch-queue branch (Closes: #1128876)
 .
   [ intrigeri ]
   * [77d16c3] Don't install AppArmor policy anymore
     (Closes: #1128672, #1127710, #928178, #909281, #955380, #882218, #900210,
      #914403, #917613, #949450, #880424, #883245, #961269, #949649)
Checksums-Sha1:
 1e9bca601d3dab684f2c1e34bbd107712eb17f8e 8402 thunderbird_152.0-1.dsc
 5ed145d0f72ee7e539f3f0d40cea83ed62b1499f 12403192 thunderbird_152.0.orig-thunderbird-l10n.tar.xz
 dbef2f6a94cec7b667931b222bdd6f0aaf9a4810 931861244 thunderbird_152.0.orig.tar.xz
 6fc9531bd0e3c27e7908228227a542966eb827f8 537512 thunderbird_152.0-1.debian.tar.xz
 41476b21bed4090bcf2c148b0178ef52d0e2f2e7 40158 thunderbird_152.0-1_amd64.buildinfo
Checksums-Sha256:
 8d348b506605fc73d56722d5a55ed9dae8af623989312e5c039786edfbe4f0f2 8402 thunderbird_152.0-1.dsc
 f4afa9846377239357e485da027035fe53762cc8100ced5cf5abca87fca7a1f8 12403192 thunderbird_152.0.orig-thunderbird-l10n.tar.xz
 64f02562f1f4a18e39c67b07255feb5828acde86327f55b1ebe45e3ac63963ea 931861244 thunderbird_152.0.orig.tar.xz
 52abff98afbeb3859791f46e5602bbbf6982f38876f7e223d0ff1ac7bb77c778 537512 thunderbird_152.0-1.debian.tar.xz
 38ab10bf14449c38f7233f8d883b1a6ffbe412606232763f9bcaa5dcda320c03 40158 thunderbird_152.0-1_amd64.buildinfo
Files:
 cddc168c5e8bdb4c051a11b4e56831b8 8402 mail optional thunderbird_152.0-1.dsc
 27c69983d0063061996fc52794377743 12403192 mail optional thunderbird_152.0.orig-thunderbird-l10n.tar.xz
 f49e9b967f1a1fdceec316060aef4959 931861244 mail optional thunderbird_152.0.orig.tar.xz
 d435a5b441fa39456dfa21b01881fdf3 537512 mail optional thunderbird_152.0-1.debian.tar.xz
 20c10b422095bf9f1d461c01e152c30e 40158 mail optional thunderbird_152.0-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmo5mL4ACgkQgwFgFCUd
HbCPqw/+LEBi5TrBqIfSUOoosSHHufs3R4FzJrZ6vNsK4ur6EVNNhR1u0Gc4VtEG
JIaiGg7fCDf3mgAowEIKSQpVHnqMPKpqZemfIWHNT0exdKp1RXlh9OuwGdOqg0Og
5MWrhKzrDVr7p9LmB7ilQ2V0I+xHx1zh/cG58Ar2Pp9Wn8YDlpIQmO0vp6sX2ex5
GTUYHvVrssW4L/hOAsbMu9YUnGPRiHPvj94JF7XT2JFC6mndXtiqvEOH5Oo1UluK
FcM8Xz1GsANmwB4gR7/g0f06RWEjAsOMXPU98ESaY85kRTJ4VlVvGWOknGa0Sptv
frrEG893xRFXFmnrDR7dLH8Ux1cnsGy5wpNCZeLVViuT6Pv4OIm83jijKqaGHvp3
jdD8OWx7YGbYdm+INBBnff5Y/IEEni7EIuX17/S3ZNqlLYJGPbL6OWG+pMK52+xZ
0dMFXCrSMc+xMMUHBQ/aUw3up5t4B5de51tX9kWTFv3W/qIiLdA+PpH2EGiJJJIF
Jgm9q0sAlXLC2GZW55MTbk2/jhewQOcShIRrEKFJUPzpPgeXZAAN/I47uKAzoUAW
0x/Hb0+b72NKBlK8jurZfKYBDPyxLnHSUcCbVCPj8SyzxcCHBZ12jsVhIEjUwMEH
cyFP/Ep5MDC7yo9XX+Xt4na47jktwLRJ5jRpySaIV9RfhvBHPNQ=
=jjF1
-----END PGP SIGNATURE-----

#949649#19
Date:
2026-09-02 17:37:23 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
thunderbird, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 949649@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Carsten Schoenert <c.schoenert@t-online.de> (supplier of updated thunderbird package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 01 Sep 2026 19:03:49 +0200
Source: thunderbird
Architecture: source
Version: 1:153.2.0esr-1
Distribution: unstable
Urgency: medium
Maintainer: Carsten Schoenert <c.schoenert@t-online.de>
Changed-By: Carsten Schoenert <c.schoenert@t-online.de>
Closes: 880424 882218 883245 900210 909281 914403 917613 928178 949450 949649 955380 961269 1127710 1128672 1145329
Changes:
 thunderbird (1:153.2.0esr-1) unstable; urgency=medium
 .
   [ Carsten Schoenert ]
   * [cb6c2c5] Merge tag 'debian/1%153.1.0esr-1' into debian/sid
   * [3c5e98e] d/gbp.conf: Adjust upstream branch to new ESR cycle
   * [628233d] New upstream version 153.2.0esr
     Fixed CVE issues in upstream version 153.2 (MFSA 2026-88):
     CVE-2026-84639: Uninitialized memory in MIME parsing
     CVE-2026-84640: One byte overflow read in mail parser
     CVE-2026-84641: Information disclosure due to malicious IMAP server
                     response
     CVE-2026-84637: Calendar invitation attachments could launch local
                     executables
     CVE-2026-84642: Allowed UNC hostnames for attachments interpreted as a
                     regular expression
     CVE-2026-75874: Sandbox escape in the Remote Settings Client component
     CVE-2026-84118: Use-after-free in the JavaScript: GC component
     CVE-2026-84119: Sandbox escape due to use-after-free in the DOM:
                     Navigation component
     CVE-2026-84120: Use-after-free in the Audio/Video component
     CVE-2026-84121: Sandbox escape due to use-after-free in the DOM:
                     Security component
     CVE-2026-84122: Use-after-free in the Audio/Video component
     CVE-2026-84123: Privilege escalation due to use-after-free in the
                     Graphics: WebGPU component
     CVE-2026-84124: Use-after-free in the DOM: Core & HTML component
     CVE-2026-84125: Use-after-free in the DOM: Core & HTML component
     CVE-2026-74952: Privilege escalation in the Application Update component
     CVE-2026-84129: Site isolation issue in the DOM: Navigation component
     CVE-2026-84130: Information disclosure in the Graphics: WebGPU component
     CVE-2026-84131: Privilege escalation due to invalid pointer in the
                     Graphics component
     CVE-2026-84132: Information disclosure in the Networking: HTTP component
     CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions
                     component
     CVE-2026-84134: Other issue in the Profile Backup component
     CVE-2026-84136: Other issue in the DOM: Navigation component
     CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component
     CVE-2026-84139: Clickjacking issue in the DOM: Events component
     CVE-2026-84140: Site isolation issue in the DOM: Navigation component
     CVE-2026-84141: Integer overflow in the Graphics: ImageLib component
     CVE-2026-84143: Internally found bugs fixed in Thunderbird 155,
                     Thunderbird ESR 153.2 and Thunderbird ESR 140.15
     CVE-2026-84144: Internally found bugs fixed in Thunderbird 155 and
                     Thunderbird ESR 153.2
     CVE-2026-84145: Internally found bugs fixed in Thunderbird 155,
                     Thunderbird ESR 153.2 and Thunderbird ESR 140.15
     (Closes: #1145329, #1128672, #1127710, #928178, #909281, #955380, #882218,
      #900210, #914403, #917613, #949450, #880424, #883245, #961269, #949649)
Checksums-Sha1:
 bac4eb72b9649c816760856964d09c076e38faf5 8422 thunderbird_153.2.0esr-1.dsc
 fe79aa4defdc8020c7a02c6df6bb7b563f36adfb 12815688 thunderbird_153.2.0esr.orig-thunderbird-l10n.tar.xz
 233dca2b586cd5c74b64334dce706f1e3ca00b80 904710156 thunderbird_153.2.0esr.orig.tar.xz
 b7cdeda74917b707b255c13b708b09157c5e7db8 556104 thunderbird_153.2.0esr-1.debian.tar.xz
 791e62c718ff9918ea5877797a45c0d22738ea38 41146 thunderbird_153.2.0esr-1_amd64.buildinfo
Checksums-Sha256:
 d77eab67b96ee31524426926ef06a4e48ac3b2415ea96d1a7f2128e77ca99ad0 8422 thunderbird_153.2.0esr-1.dsc
 c33e07a872d250687088a407ce054593f6b0c2f5683e9af8f6632cdeb9700553 12815688 thunderbird_153.2.0esr.orig-thunderbird-l10n.tar.xz
 79c01aa5b07f3464d43cc96300141b678a2685c861b9bcc6890e9e6d088f1aeb 904710156 thunderbird_153.2.0esr.orig.tar.xz
 533a8015c15e833508f91e121182c5426af50c22ab56a0f1081c0fdda20f39e9 556104 thunderbird_153.2.0esr-1.debian.tar.xz
 f241204d92ccbacd2171d1e9f151875e6211f07ba8339177364a68d98cca2f95 41146 thunderbird_153.2.0esr-1_amd64.buildinfo
Files:
 ed3769dd9d71c325b0279905fdb13bb5 8422 mail optional thunderbird_153.2.0esr-1.dsc
 86caafe71439920cf8a6654c990c9fa2 12815688 mail optional thunderbird_153.2.0esr.orig-thunderbird-l10n.tar.xz
 b2c0d7f65a9cd572aa2a1f30644775cc 904710156 mail optional thunderbird_153.2.0esr.orig.tar.xz
 2ef3d8fe96862cfda6fcee8e46c50a71 556104 mail optional thunderbird_153.2.0esr-1.debian.tar.xz
 dfc69d6380f67a4b97137b4f7fe5d71b 41146 mail optional thunderbird_153.2.0esr-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmqYPuMACgkQgwFgFCUd
HbDucw//V9bDtLsvpm/xw02HRxdA7FPVmYjP9k4oWIf634i82Cu+o8UHksHNYfip
qCMpgrwR+LXPDfnF/UZeW8AaMvX69C3Be2b33TB/7Cgjo9kIJI0/4IhKhp0CJiwn
jjtRkyVNLDDDYMNJU4pbkQR/PDlyjG2N/RSqfylR/iC1KUO70D6XkIAkw6AoUEoP
1s+Ly52fdF6SSvLRwcTQtt/k7xKRILVIda+uDey/LAz40TszDTbwbSrY+/tkWBtW
5aLA+eE6YR/aKxlW7+rUj1IhaW0FzlAEbUCrl2li5l0oSw4JqqPGmYSUuQyfJXI1
V8eytDOU5tl8uYGb1ixlYB5nmbRrT815bBw0Fddw5rR+7j9QD/QlSRfOHgP+ppm5
bWfyiPaI0mCUTm5trv6ECl3BZC4/rpWAmn80ucxfJoocqlEl+mALDV5DCz0sSU4p
ErQ8zZYHZfgfiZbwSi2jElhUwWvAD8r0AmsZSxaZJEjRQeq+DGj56kK0+mnpIMQ1
hzWr1OBr+Tt2FZw4n94GAZ077U8SFlGTQSMTdk+vaT6wypuWY2TtJqiPW2uk8B1v
2HZd5KIBFdYgiChNyZEa1RpfCX+xhjXIdE6jc1yhpZ8rmwHLVVzY4nfaUCoXm70E
OcNnneYzELnz8mbI3NXZ9iyjPXAMdyskdSijmOgPMlC7pNh0pks=
=sQE4
-----END PGP SIGNATURE-----