-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 03 May 2023 00:42:00 -0500 Source: chromium Binary: chromium-l10n Architecture: all Version: 113.0.5672.63-1~deb11u1 Distribution: bullseye-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Timothy Pearson Description: chromium-l10n - web browser - language packs Closes: 992178 1031352 Changes: chromium (113.0.5672.63-1~deb11u1) bullseye-security; urgency=high . * New upstream stable release. - CVE-2023-2459: Inappropriate implementation in Prompts. Reported by Rong Jian of VRI. - CVE-2023-2460: Insufficient validation of untrusted input in Extensions. Reported by Martin Bajanik, Fingerprint[.]com. - CVE-2023-2461: Use after free in OS Inputs. Reported by @ginggilBesel. - CVE-2023-2462: Inappropriate implementation in Prompts. Reported by Alesandro Ortiz. - CVE-2023-2463: Inappropriate implementation in Full Screen Mode. Reported by Irvan Kurniawan (sourc7). - CVE-2023-2464: Inappropriate implementation in PictureInPicture. Reported by Thomas Orlita. - CVE-2023-2465: Inappropriate implementation in CORS. Reported by @kunte_ctf. - CVE-2023-2466: Inappropriate implementation in Prompts. Reported by Jasper Rebane (popstonia). - CVE-2023-2467: Inappropriate implementation in Prompts. Reported by Thomas Orlita. - CVE-2023-2468: Inappropriate implementation in PictureInPicture. Reported by Alesandro Ortiz. . [ Andres Salomon] * Remove Michel from Uploaders. * Build against libopenh264-dev (closes: #1031352). * d/copyright: - drop fuchsia*: entirely different OS. - drop chrome/build: 200MB of PGO optimizations for official chrome builds. - drop third_party/updater: upstream included update binary. - re-add part of chrome/browser/resources/chromeos/ and chrome/android/ to fix build errors. * d/patches: - debianization/master-preferences.patch: check for initial_preferences or master_preferences, rather than just for the latter (closes: #992178). - disable/unrar.patch: complete rewrite for upstream's nested archive changes. - disable/catapult.patch: refresh. - upstream/webview-cstr.patch: add simple build fix from upstream. - upstream/monostate.patch: add simple build fix from upstream. - bookworm/clang-attribs.patch: build fix for clang-14 to keep from generating hundreds of warnings per compilation unit. - bookworm/typename.patch: add another build fix for missing typename. - bookworm/lamba-bug.patch: add to work around compiler bug (clang < 16). - bullseye/constexpr.patch: work around build failure w/ bullseye's clang/libstdc++. - disable/openh264.patch -> bullseye/openh264.patch, and stop using it for sid & bookworm. - bullseye/disable-mojo-ipcz.patch: refresh. - bullseye/mulodic.patch: refresh. . [ Timothy Pearson ] * d/patches: - Set baseline ppc64 CPU to POWER ISA 3.0 (OpenPOWER, POWER9) - Enable VSX acceleration in Skia - Refresh ppc64le/third_party/0002-third_party-libvpx-Remove-bad-ppc64-config.patch - Add fixes for new Highway library on ppc64 - Suppress harmless warning messages from compiler during ppc64 builds Checksums-Sha1: 8f729a16f3876ae352eb561f05f6159febce6a0c 6109896 chromium-l10n_113.0.5672.63-1~deb11u1_all.deb 2d2819e950c20b8d9bc378b1294e3fd452f6df17 22856 chromium_113.0.5672.63-1~deb11u1_all-buildd.buildinfo Checksums-Sha256: a5cf87df87f096da0200d71f05f2366d6d1b820870db0dd61dc54d8baa6b51ec 6109896 chromium-l10n_113.0.5672.63-1~deb11u1_all.deb 11a2972404bc6719aeaf3f0b6db2864ffb8329b90b942dc18748ca96f09a582e 22856 chromium_113.0.5672.63-1~deb11u1_all-buildd.buildinfo Files: 311a52bca2fcf863ba25768b728bf3ec 6109896 localization optional chromium-l10n_113.0.5672.63-1~deb11u1_all.deb 03faeea2214388123a53f546e5faa42a 22856 web optional chromium_113.0.5672.63-1~deb11u1_all-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEi/TVpVg0yb7dq8QfDZWW6X29YdoFAmRScRUACgkQDZWW6X29 YdrbVQ//cZOEukhoAPsoKhCAmboyNckYlW5xWUTN/M+7ttAGlvvYVM1ikZ5M1vXy ZElBJm3SBIqRIgn+beUQw8GqzeV+7sDYN+f+BxnGKo3QAvH0V1BgIwVBk1x8W0iy viMp0QcL9m1sAKw2oXVkDJh4/O8VgmBiS9FucVt+te37UDfxj1xtacwkoPSe0a0K IuRtv7fJoGd3vKO/sYZqQvFvAHbzeqwcZDYSp4A48A+wpPLbIyhMX7me1c6mwHs6 j35O4mFaMufvfhTBwZrh+v5mUzI+9GRt9WGsPzbF/M8rbGUyK2ZiWA5qnj9o6iIN khbxly+RQzdvhW8xGYgZNAZYTjW/BB6LL8SSAuWOiBR5Y5XfDudpg0d2flnhaWOM 0YMHHXGjeR5L4NzZFiA/Prm0fc1R0lUUR1T2AnEO8nvW3hbsPMl9a2hBm597ax7R SME2Zudnn8mE14Ogus4zo1gft3RfYQVAAE+qY0Wl5CPl4v9vLoVbogfYTm9EdZYx G/EIcMVnvUO0O1zpiLOuBPOXjOhNzjYl1UuP8/LxJIBApvgahoASlOySFoDVxCsY nROfYFThncCJVZGoQqTBCTOoJHQOWT5Jluykz/Ji2X5xYsV6yA3Ys1t9/h8WMcjD g74x+p1O4idm133GY1tJP4GMoUop9iAtxmsxeXJfb/XI5BdCmsI= =zX/w -----END PGP SIGNATURE-----