-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 28 Sep 2023 00:41:20 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: amd64 Version: 117.0.5938.132-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-conova-02) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Closes: 1053142 Changes: chromium (117.0.5938.132-1~deb12u1) bookworm-security; urgency=high . * New upstream security release. - CVE-2023-5217: Heap buffer overflow in vp8 encoding in libvpx. Reported by Clément Lecigne of Google's Threat Analysis Group. - CVE-2023-5186: Use after free in Passwords. Reported by [pwn2car]. - CVE-2023-5187: Use after free in Extensions. Reported by Thomas Orlita. * d/patches: - bookworm/i386-lock-free.patch: add to fix i386 build failure. - bookworm/freetype-COLRV1.patch: disable using freetype's COLRV1 (closes: #1053142). Checksums-Sha1: 12f4aa4205325e634b4275ac7f0f05ca3193fb9d 1204588 chromium-common-dbgsym_117.0.5938.132-1~deb12u1_amd64.deb fc6d13f162b4853ee32da5120a8a6b684f122874 4977148 chromium-common_117.0.5938.132-1~deb12u1_amd64.deb a1f359864c7a2a0c3dfbfca021dd354830d18a3d 31252740 chromium-dbgsym_117.0.5938.132-1~deb12u1_amd64.deb cb2275e9c4d8aff61771761bf980ed0c3cfc733a 5346076 chromium-driver_117.0.5938.132-1~deb12u1_amd64.deb 7f94a0375d3a61f3eadcdedf5d98d8f91851a93d 12648 chromium-sandbox-dbgsym_117.0.5938.132-1~deb12u1_amd64.deb 678dd61e4e7f0c9865118b78990e883a04f37c5e 82228 chromium-sandbox_117.0.5938.132-1~deb12u1_amd64.deb 00b111468bccc9be4faeea8dbc2b234a7dce9fc5 26587708 chromium-shell-dbgsym_117.0.5938.132-1~deb12u1_amd64.deb d07712785b97237d645d404e5af622322e319904 49550640 chromium-shell_117.0.5938.132-1~deb12u1_amd64.deb 0baf4539a1d124cfd5311c4e45bc0ededd3f35d1 24064 chromium_117.0.5938.132-1~deb12u1_amd64-buildd.buildinfo 9189e38f87bb9a3949248d8f2b2892e1059ccb5d 70862300 chromium_117.0.5938.132-1~deb12u1_amd64.deb Checksums-Sha256: 112b0fa0d95f927ef7ab8946f4e8fb3e3a4bf4daf4b16291e93866864a48d62b 1204588 chromium-common-dbgsym_117.0.5938.132-1~deb12u1_amd64.deb 9731c7f2fe84ef900d9484367d8bebc9679b424478e52b8cf9e247c395483a80 4977148 chromium-common_117.0.5938.132-1~deb12u1_amd64.deb 41abb2327e5ee59492a240be10df328310d979e88b1b89beb0a5c23758521f3b 31252740 chromium-dbgsym_117.0.5938.132-1~deb12u1_amd64.deb 1f961ad28ed789c150044d2d65ebfff2d266955cbf0e3495c6f7067f1b08f94d 5346076 chromium-driver_117.0.5938.132-1~deb12u1_amd64.deb a1a7024dccb2adedee3821541803ed929de70d8e295b1f78186e55280e7405f8 12648 chromium-sandbox-dbgsym_117.0.5938.132-1~deb12u1_amd64.deb fc91b957ca3b71aaf9b1bbdef4bce97e5314a8dd2d4c688c5015e8d8d4fb0ab2 82228 chromium-sandbox_117.0.5938.132-1~deb12u1_amd64.deb f6e3b9c7e5f194be6e62c5b8a1a4560bb100163d6a0b566fd641b0e38e38b6c4 26587708 chromium-shell-dbgsym_117.0.5938.132-1~deb12u1_amd64.deb db15ca835095350d4cd034b95dae87f27671b4df9fae8769f9719c92bc61a618 49550640 chromium-shell_117.0.5938.132-1~deb12u1_amd64.deb 2b65f7f1efd1134f73a51bf4e4b40c302dda35ff89567554ebf9e04375c47109 24064 chromium_117.0.5938.132-1~deb12u1_amd64-buildd.buildinfo 114022a6e47f40832688690d9b88079fb3fa7a2baf12709986500d182e43dad6 70862300 chromium_117.0.5938.132-1~deb12u1_amd64.deb Files: 1979b3cad2c3eed6288e426b8d5df41a 1204588 debug optional chromium-common-dbgsym_117.0.5938.132-1~deb12u1_amd64.deb 77b8c0dbb8a6f360d053ea37e660453f 4977148 web optional chromium-common_117.0.5938.132-1~deb12u1_amd64.deb 37f64bfa53cd1eda7f7e000753a104a8 31252740 debug optional chromium-dbgsym_117.0.5938.132-1~deb12u1_amd64.deb 1b4a8e3749d1e082267710dda67241b2 5346076 web optional chromium-driver_117.0.5938.132-1~deb12u1_amd64.deb dea7e4c0a66c7fe37a7b9a5e4133272a 12648 debug optional chromium-sandbox-dbgsym_117.0.5938.132-1~deb12u1_amd64.deb 0eb39182213732223e5d2add257e4d96 82228 web optional chromium-sandbox_117.0.5938.132-1~deb12u1_amd64.deb d4545c756fa0f04d325f83dbd0ec0448 26587708 debug optional chromium-shell-dbgsym_117.0.5938.132-1~deb12u1_amd64.deb 5243a4eb5ffdf8d9d6f632a8c0c27075 49550640 web optional chromium-shell_117.0.5938.132-1~deb12u1_amd64.deb 911447321b8ec527b7eb361c591b73b0 24064 web optional chromium_117.0.5938.132-1~deb12u1_amd64-buildd.buildinfo 8562cbf875e574e8302034c8d55cc077 70862300 web optional chromium_117.0.5938.132-1~deb12u1_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEOtJZa9Q/HRv7PgxxkF7E12VCox0FAmUWJDQACgkQkF7E12VC ox1JHQ/+OMwGl3GdF0V5K9nfccDqX/l/dvhcUG40iHbZHAJ5vqdRDbLXnMwMtJBT 9C/MTz1d6jOPYW8DICFXesEtPO2jnrwPxbHFIDhMTIbw4Y8vssgViLliVEdx18dD hXcTe1R21pbmo4U2crGwkZiScMGpy5czSYXnPEzCu/H1jbOxLSKZu2Ad2bhbuVG0 f28GAG3nneTunqMPDMewUVP0e0K3mBjUsO63Y75UZkXCf6L/OcswNhqBxPpSQfHS i8eOSz8/8fB7gvA/Xmym7YF5vrEWnbkzmOiiQy9Alzo9nkUC7yR1QVHIvCq9hw8z HMUUeaLReaDUJdjrC+BcIMjgIzs+bbaEwLaAfKXUnMbA1Ze92c61P9U/abwjq50N S6b7BwiPBwGbVLCP2G3Pid8pxtuiPUAw28S1sdrGpBg3PRXMw62+t5Y0ppQXY1wr 1xbZw+gOwPtwyaB+o2ZomxkrN945V7XjoHl2/jBUkX6SZbzT+C1H9eVFgcAwgtSU H+lx1zos9YK//WuicRiE3Np/PYOlqFEUAJQ18YOG8R2iVbblxW/K3emWjov4gnmF tkeRm9RwOakXpOw7UQAHXumZZ7mJWHpCYLAUwpYkUVYFHsEHxcikvtjugiiG3Fvd pueFHiqhZVMmERGOD9mrOuGljaiXOgb9Qpr7CLTYsVTrmfdsTkw= =fsjJ -----END PGP SIGNATURE-----