Looking at the upstream security advisory linked, I can't find any CVEs
that are still open in Ubuntu. I checked all the ones categorised by
upstream as Critical or High, and Ubuntu's CVE database shows them all
as having fixes published in Ubuntu already.

It seems to me that this is therefore not a security issue.

Please confirm by looking for a CVE that isn't fixed by examining
Ubuntu's CVE Tracker at https://people.canonical.com/~ubuntu-
security/cve/. If you can find a CVE number that is specifically not
fixed, then please highlight that here. Going just on the basis of the
version number is not sufficient and is an FAQ item:
https://wiki.ubuntu.com/SecurityTeam/FAQ#Versions

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to thunderbird in Ubuntu.
https://bugs.launchpad.net/bugs/1796126

Title:
  Thunderbird is out of date for two months when Thunderbird 60 was
  released

Status in thunderbird package in Ubuntu:
  Confirmed

Bug description:
  Thunderbird is one of the most used email clients. Thunderbird 60 has
  been released on 2018-08-06 what is two months ago
  (https://www.thunderbird.net/en-US/thunderbird/60.0/releasenotes/). As
  usual there have also been fixes for at least eight critical and high
  security bugs (https://www.mozilla.org/en-
  US/security/advisories/mfsa2018-19/).

  1) $ lsb_release -rd
  Description:    Ubuntu 18.04.1 LTS
  Release:        18.04

  $ apt-cache policy thunderbird
  thunderbird:
    Installiert:           1:52.9.1+build3-0ubuntu0.18.04.1
    Installationskandidat: 1:52.9.1+build3-0ubuntu0.18.04.1
    Versionstabelle:
   *** 1:52.9.1+build3-0ubuntu0.18.04.1 500
          500 http://de.archive.ubuntu.com/ubuntu bionic-updates/main amd64 
Packages
          500 http://security.ubuntu.com/ubuntu bionic-security/main amd64 
Packages
          100 /var/lib/dpkg/status
       1:52.7.0+build1-0ubuntu1 500
          500 http://de.archive.ubuntu.com/ubuntu bionic/main amd64 Packages

  3) Firefox and Thunderbird have been updated quite closely to the
  upstream releases even for old LTS releases.

  4) Thunderbird got no update since 2018-07-03
  
(http://changelogs.ubuntu.com/changelogs/pool/main/t/thunderbird/thunderbird_52.9.1+build3-0ubuntu0.18.04.1/changelog)
  despite the new version 60. For upcoming Ubuntu 18.10 there even is an
  older version 52.7 version available
  (https://packages.ubuntu.com/cosmic/thunderbird). Debian Sid has a
  60ish version (https://packages.debian.org/sid/thunderbird) that may
  be reused.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/1796126/+subscriptions

-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to     : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to