-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 28 Sep 2023 00:41:20 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: arm64 Version: 117.0.5938.132-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-conova-02) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Closes: 1053142 Changes: chromium (117.0.5938.132-1~deb12u1) bookworm-security; urgency=high . * New upstream security release. - CVE-2023-5217: Heap buffer overflow in vp8 encoding in libvpx. Reported by Clément Lecigne of Google's Threat Analysis Group. - CVE-2023-5186: Use after free in Passwords. Reported by [pwn2car]. - CVE-2023-5187: Use after free in Extensions. Reported by Thomas Orlita. * d/patches: - bookworm/i386-lock-free.patch: add to fix i386 build failure. - bookworm/freetype-COLRV1.patch: disable using freetype's COLRV1 (closes: #1053142). Checksums-Sha1: cf99b5937b17af0caac06ad10e7b222940902f14 1229048 chromium-common-dbgsym_117.0.5938.132-1~deb12u1_arm64.deb 71cd7103f54a056bb264babd8603cb1bf5bf0363 4818928 chromium-common_117.0.5938.132-1~deb12u1_arm64.deb 9a829b620ce6ef88b40a2e1492e654fd3c55ca21 28911004 chromium-dbgsym_117.0.5938.132-1~deb12u1_arm64.deb c7c0d301018e1eb51e04fa7cfa64be30cc1a674d 4828252 chromium-driver_117.0.5938.132-1~deb12u1_arm64.deb 7abcf1d0ceae0f6827f5f35c1b4f4972b5e6bd54 12908 chromium-sandbox-dbgsym_117.0.5938.132-1~deb12u1_arm64.deb 11e9a9fd59ee1a703067333a5b0c97c941f1604b 82128 chromium-sandbox_117.0.5938.132-1~deb12u1_arm64.deb 94ea3adf0ae3ef7913a1814796bd280dc8bfd541 23502852 chromium-shell-dbgsym_117.0.5938.132-1~deb12u1_arm64.deb e7a024a074fa4c76f4f70a483acc2c95ea300382 43658996 chromium-shell_117.0.5938.132-1~deb12u1_arm64.deb 4e1b5e39de7b179e9a7f11a21751f52a1cdcfe55 24135 chromium_117.0.5938.132-1~deb12u1_arm64-buildd.buildinfo 15d60ca87e6abc28a1600339f004e1d37eb765fc 62780896 chromium_117.0.5938.132-1~deb12u1_arm64.deb Checksums-Sha256: dc719f0acd7726aa62cbfc2410f8ecc49541d3cf6d2a494fd32810fa085354a7 1229048 chromium-common-dbgsym_117.0.5938.132-1~deb12u1_arm64.deb c3d09d3f5f5a7e27996c04a40253c7c7e968f4f236607de779adcf9a561bff7b 4818928 chromium-common_117.0.5938.132-1~deb12u1_arm64.deb a9e51f983f0fbcdc89743bb52fb43b2d5feed19ac0ffd819d3a8bb0b8ff84c40 28911004 chromium-dbgsym_117.0.5938.132-1~deb12u1_arm64.deb 9678b41d6e7093c8a968246ec1505d35f5da570062f217cebe177c4e55d0f2c9 4828252 chromium-driver_117.0.5938.132-1~deb12u1_arm64.deb f102fa863b5a0be6e813e4e0b827fb7ebc0ff15d03f58c928b3581fff4405878 12908 chromium-sandbox-dbgsym_117.0.5938.132-1~deb12u1_arm64.deb 951c08d7b8600df1a7bff7184191382f67949959b3cd1e50c770173104fcf5a3 82128 chromium-sandbox_117.0.5938.132-1~deb12u1_arm64.deb d2bd52ae6776914435ad55e6ce3a813c9b0047d8f78389ef32a6771b6c2546b5 23502852 chromium-shell-dbgsym_117.0.5938.132-1~deb12u1_arm64.deb c8ca48a4e45a188dbf96a295ec264908f29fd52c7354c8c69b3c2a0865f8cf72 43658996 chromium-shell_117.0.5938.132-1~deb12u1_arm64.deb 4ad5dcbc21e463c7443c7bf45fa4a1eda06c4c92db97bd41a98d8159b0814bfd 24135 chromium_117.0.5938.132-1~deb12u1_arm64-buildd.buildinfo 11a54f89daed6fa2d3c11237211afac262190abfa26bc50166cf5dbd772cfab2 62780896 chromium_117.0.5938.132-1~deb12u1_arm64.deb Files: 5baae2ddbce01b8be131a0f4a01cc39b 1229048 debug optional chromium-common-dbgsym_117.0.5938.132-1~deb12u1_arm64.deb ba3810e12bf61b24023b56d178cc81d8 4818928 web optional chromium-common_117.0.5938.132-1~deb12u1_arm64.deb 40e551b2a57d36a61dedb3d330878205 28911004 debug optional chromium-dbgsym_117.0.5938.132-1~deb12u1_arm64.deb e4d710e20d2453c1c4a5646b7eeca246 4828252 web optional chromium-driver_117.0.5938.132-1~deb12u1_arm64.deb 5d7ee106ff4c6f84e597406d37a58f08 12908 debug optional chromium-sandbox-dbgsym_117.0.5938.132-1~deb12u1_arm64.deb 07308f93d8d16fa024b85b79b9290af3 82128 web optional chromium-sandbox_117.0.5938.132-1~deb12u1_arm64.deb f26959a9e9ff86bfb51521d72b84ebf0 23502852 debug optional chromium-shell-dbgsym_117.0.5938.132-1~deb12u1_arm64.deb f255135959370053c491e1cdfc0a381d 43658996 web optional chromium-shell_117.0.5938.132-1~deb12u1_arm64.deb c27340bf4d66cee26ad55d7f5dfeb79b 24135 web optional chromium_117.0.5938.132-1~deb12u1_arm64-buildd.buildinfo b6092afe9cf3d08d44ffa7766c53cac9 62780896 web optional chromium_117.0.5938.132-1~deb12u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEBv+o19JDIRm4yIQ5CeROIpkCGwcFAmUZhoEACgkQCeROIpkC GwdmUQ//Zg33UPIxmYQUUJMPSi45zavhhZHjRK8XuXPz4IPXqhlEhBA9EFPYHAes fwxySjzAsYyd8Jc3ZKbYkVcU6gfFOnayDGJc+OVn+n7BIS0YrGVz01HH0wN58E8d 7E4AWG6jri7R6V9rA/wxNlRtnJfJmVLy1XgHkm8RDDhZrRpfSJPMC1blHJERGCYq T+ObyDNwZGOlsQF7yOxab6gQFYiRzMr7UN/VzoriCAE282YcQgshoaGQ7dy6pggf KGYalwn6G56whfk0eS8PeFwkj3P1f5Azv94ymt1J3bKRB0kDNz1MR8AWQznWS8/m NnbzbfCDPt5vU1G/1U0eYzUwfFQLs1OB4Wu3HTEqi0szIJeAd+m24zBkEzrAez4G +kzE7Xmku+PA+8Kgo0libNh3DN/y6m8Lva3NUFG/Fl2AHFP9BEPgoEiOEGGoKfO0 5Kcj+v/Q3tn3VjFq/tEv+7nmkPej/QCuO0ajmBB+f0OmViOHR0F0rzy6wyC0QPbZ /Xs3e6LZxVjSRe3iFFEV8IPq/SI+anoRr12701OnIFcWP6UhISmGAvRJUezHvFsK cSCO5BeJespSgh+i3kn5Ps0PCRJuehVWO5E7r+BZAn9XMn6NnS2mTrVpSrUGF/Qf a7ZP8sbwXCdYvdXzGsjTeNuRP3Xd71PG9EeDl4rjDhMw8Xl6IaU= =9vEH -----END PGP SIGNATURE-----