-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 28 Sep 2023 00:41:20 -0400 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: i386 Version: 117.0.5938.132-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-02) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Closes: 1053142 Changes: chromium (117.0.5938.132-1~deb12u1) bookworm-security; urgency=high . * New upstream security release. - CVE-2023-5217: Heap buffer overflow in vp8 encoding in libvpx. Reported by Clément Lecigne of Google's Threat Analysis Group. - CVE-2023-5186: Use after free in Passwords. Reported by [pwn2car]. - CVE-2023-5187: Use after free in Extensions. Reported by Thomas Orlita. * d/patches: - bookworm/i386-lock-free.patch: add to fix i386 build failure. - bookworm/freetype-COLRV1.patch: disable using freetype's COLRV1 (closes: #1053142). Checksums-Sha1: fba9a8dad40e4cb274293048851f2f0bed99308e 1142536 chromium-common-dbgsym_117.0.5938.132-1~deb12u1_i386.deb ee412068a5c814833f652aa19140cdb512400749 4976276 chromium-common_117.0.5938.132-1~deb12u1_i386.deb 10d3994b70ff2fe414f54133007235d0f335cf1f 30152444 chromium-dbgsym_117.0.5938.132-1~deb12u1_i386.deb 7d056dedb9eb1ce0f7418725f4d9a77d5879ce3e 5970760 chromium-driver_117.0.5938.132-1~deb12u1_i386.deb 08728682def81131d02c71d3330305d1c96d316d 12580 chromium-sandbox-dbgsym_117.0.5938.132-1~deb12u1_i386.deb d8ca7a7dd0fb44b63165512d3d09fa3bf0cccfb0 82136 chromium-sandbox_117.0.5938.132-1~deb12u1_i386.deb b954572d9bba961d6e403686a33ddd628d58a8ac 25589456 chromium-shell-dbgsym_117.0.5938.132-1~deb12u1_i386.deb 146a1440adfb2584a4ac66740fa62262b2ce2fa7 50278052 chromium-shell_117.0.5938.132-1~deb12u1_i386.deb 45d3df4f07e51e10bd8461c966d5e2b276cbb065 24030 chromium_117.0.5938.132-1~deb12u1_i386-buildd.buildinfo 5ff340fefbe18e0e886cd368d8c4ac31107db798 72301572 chromium_117.0.5938.132-1~deb12u1_i386.deb Checksums-Sha256: c2b9e6250b29e2e1072ca25119b7e79ed620a96ea367050bb907e6ad4827147d 1142536 chromium-common-dbgsym_117.0.5938.132-1~deb12u1_i386.deb 219f99a98d252001211cc9bb2decd47c99e67c40801d48f4b612baad96225229 4976276 chromium-common_117.0.5938.132-1~deb12u1_i386.deb 109d7950bc6ebd7d7fbc211bb340357a57f71b4ca37d3cb5d9864eb8fbc6ad40 30152444 chromium-dbgsym_117.0.5938.132-1~deb12u1_i386.deb 8e8b0c8a7edad7e8f11870615f7c3ed74287b940c75f5654651a6507604878ce 5970760 chromium-driver_117.0.5938.132-1~deb12u1_i386.deb ca4daaf26ec24979db95d77aafcaee8c069766a6c291320b36242519ed5390e3 12580 chromium-sandbox-dbgsym_117.0.5938.132-1~deb12u1_i386.deb aa550984512df73de2e03945fc9e7faf4139044e36c8d4e9f4c8a4f91da99d39 82136 chromium-sandbox_117.0.5938.132-1~deb12u1_i386.deb dfe65ae8a6de5147e92db738e658ef61e5c36313c609dfa1868b081ed64fca9e 25589456 chromium-shell-dbgsym_117.0.5938.132-1~deb12u1_i386.deb 7432f111b16d1eb1d1fa16adf30a073313bf4ff24dc894cedabacd29a43ca829 50278052 chromium-shell_117.0.5938.132-1~deb12u1_i386.deb c91317c8995e9d5b13996dd59734b967026f8853f2c299e21575028d23ca0748 24030 chromium_117.0.5938.132-1~deb12u1_i386-buildd.buildinfo f495e51fa44cb817afd7295c43e47836c64a3e9a338bcefd4ce93bf1f99714c3 72301572 chromium_117.0.5938.132-1~deb12u1_i386.deb Files: d7ef2f375d52f6185a439283d76f65b3 1142536 debug optional chromium-common-dbgsym_117.0.5938.132-1~deb12u1_i386.deb ea6622631d2357f01394bb2687bd8745 4976276 web optional chromium-common_117.0.5938.132-1~deb12u1_i386.deb 2106e67fde7e2d3221fa4964ce66099d 30152444 debug optional chromium-dbgsym_117.0.5938.132-1~deb12u1_i386.deb a81b6a75770080a1e7fa3ca37d9534b0 5970760 web optional chromium-driver_117.0.5938.132-1~deb12u1_i386.deb 572097800c8fd6f074f53b509115e424 12580 debug optional chromium-sandbox-dbgsym_117.0.5938.132-1~deb12u1_i386.deb dd998bd54b97bca67899b8d59be6fff4 82136 web optional chromium-sandbox_117.0.5938.132-1~deb12u1_i386.deb a626c49efddbe16591c5d6af3c10a9da 25589456 debug optional chromium-shell-dbgsym_117.0.5938.132-1~deb12u1_i386.deb 672da999394f741eba937dd9c5f07387 50278052 web optional chromium-shell_117.0.5938.132-1~deb12u1_i386.deb b268878d8c2e683e0da39a6d0d7825e1 24030 web optional chromium_117.0.5938.132-1~deb12u1_i386-buildd.buildinfo 2741f61a05a88253496d39c619c59d8d 72301572 web optional chromium_117.0.5938.132-1~deb12u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEJyRdn7p9tGRfxctAots23/koc0EFAmUWt6cACgkQots23/ko c0EZEw/+PDi89vNdC/CrySFtuYrWLU3Ver7MhGowuPsRv0RfimPqJQtM2T/KOlHl HWskRREXk5aCrtdb7yrJ9HlT4eyxdAkyf2QXrA5K6G1Smc6mNFhJPHJ8AV/mmWRM uy7XWaICza4lJrERhERrfrVBrjCRROg2JsKPGEkqvq4Xi+Vtm/89p3nSMd63G6r6 das3hU01Mzc8eSF9Wy0SJ3j5Nf5IdmMtf4aBE/VNs8EJF1MMAcwW1h5vTrBs37u5 eN34AGeT1OIAJ5caDFtz6PznGquTYEOctK8ceNPsSDH4tOAZhgInolI/Y0bMKH2b h9LMpq960VwrOTXFAGBvPNBx/WHFj9hJGQQAEawdOvLn/cBbtHGj+Y3buvy41ZsF y8hrWUJ62nyfK66bApndwLcyyqLJH9XcVcnj2gKGlkwmtMKTjSE4PNPwEH6PZ2cf tpnWQnPffbgrgz+GRqzZkb2JJUXTUP9fmkFHiuBy/IGOFmfsWea/yQMbxhE3syQ9 6jJIO5IpX8PzkJaYYp/DSXeh8OyauhtNBTUqPpPrppipZUxPV0k5hKIgUKpj+S12 CGd+73ONVAHPFtkQ4DqK1/ewHbseVaXykdFZm/EAt+aFWWO+dVO3AG5vNz0toUTu nlatFncVQ2U8EZo7OxBG5Kz6rrZyJ7NkmcQbIJ0C+vWuVFzJ7Zc= =RY0H -----END PGP SIGNATURE-----