-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 03 May 2023 00:42:00 -0500 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: arm64 Version: 113.0.5672.63-1~deb11u1 Distribution: bullseye-security Urgency: high Maintainer: arm Build Daemon (arm-conova-02) Changed-By: Timothy Pearson Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Closes: 992178 1031352 Changes: chromium (113.0.5672.63-1~deb11u1) bullseye-security; urgency=high . * New upstream stable release. - CVE-2023-2459: Inappropriate implementation in Prompts. Reported by Rong Jian of VRI. - CVE-2023-2460: Insufficient validation of untrusted input in Extensions. Reported by Martin Bajanik, Fingerprint[.]com. - CVE-2023-2461: Use after free in OS Inputs. Reported by @ginggilBesel. - CVE-2023-2462: Inappropriate implementation in Prompts. Reported by Alesandro Ortiz. - CVE-2023-2463: Inappropriate implementation in Full Screen Mode. Reported by Irvan Kurniawan (sourc7). - CVE-2023-2464: Inappropriate implementation in PictureInPicture. Reported by Thomas Orlita. - CVE-2023-2465: Inappropriate implementation in CORS. Reported by @kunte_ctf. - CVE-2023-2466: Inappropriate implementation in Prompts. Reported by Jasper Rebane (popstonia). - CVE-2023-2467: Inappropriate implementation in Prompts. Reported by Thomas Orlita. - CVE-2023-2468: Inappropriate implementation in PictureInPicture. Reported by Alesandro Ortiz. . [ Andres Salomon] * Remove Michel from Uploaders. * Build against libopenh264-dev (closes: #1031352). * d/copyright: - drop fuchsia*: entirely different OS. - drop chrome/build: 200MB of PGO optimizations for official chrome builds. - drop third_party/updater: upstream included update binary. - re-add part of chrome/browser/resources/chromeos/ and chrome/android/ to fix build errors. * d/patches: - debianization/master-preferences.patch: check for initial_preferences or master_preferences, rather than just for the latter (closes: #992178). - disable/unrar.patch: complete rewrite for upstream's nested archive changes. - disable/catapult.patch: refresh. - upstream/webview-cstr.patch: add simple build fix from upstream. - upstream/monostate.patch: add simple build fix from upstream. - bookworm/clang-attribs.patch: build fix for clang-14 to keep from generating hundreds of warnings per compilation unit. - bookworm/typename.patch: add another build fix for missing typename. - bookworm/lamba-bug.patch: add to work around compiler bug (clang < 16). - bullseye/constexpr.patch: work around build failure w/ bullseye's clang/libstdc++. - disable/openh264.patch -> bullseye/openh264.patch, and stop using it for sid & bookworm. - bullseye/disable-mojo-ipcz.patch: refresh. - bullseye/mulodic.patch: refresh. . [ Timothy Pearson ] * d/patches: - Set baseline ppc64 CPU to POWER ISA 3.0 (OpenPOWER, POWER9) - Enable VSX acceleration in Skia - Refresh ppc64le/third_party/0002-third_party-libvpx-Remove-bad-ppc64-config.patch - Add fixes for new Highway library on ppc64 - Suppress harmless warning messages from compiler during ppc64 builds Checksums-Sha1: 0ced79e484e2ba4394ea581a8fa0f25c8be99e09 1121404 chromium-common-dbgsym_113.0.5672.63-1~deb11u1_arm64.deb 8b4871f453d99e75024d92df8781cec8329e7763 4807532 chromium-common_113.0.5672.63-1~deb11u1_arm64.deb a5ba1083ce6325e13598d03178760c2549806b3f 27195816 chromium-dbgsym_113.0.5672.63-1~deb11u1_arm64.deb d11205cb5ea9b71cf2b8109c8f149fcfbc4f9654 5093308 chromium-driver_113.0.5672.63-1~deb11u1_arm64.deb 7c72e44e883a36f6e235bf1759e4268179401e1a 12352 chromium-sandbox-dbgsym_113.0.5672.63-1~deb11u1_arm64.deb b9ad861fff7bd5ca8504bff62bb7b99f95553c30 132956 chromium-sandbox_113.0.5672.63-1~deb11u1_arm64.deb f4ea7ac229e33b0b5ad0ee37371fd4d24b9607aa 22546624 chromium-shell-dbgsym_113.0.5672.63-1~deb11u1_arm64.deb e6a4e774710c406f96cd63015781e42250ad852e 42472780 chromium-shell_113.0.5672.63-1~deb11u1_arm64.deb abc25c914a91dea4a7c01c1e4ac18afd0105b9e7 25508 chromium_113.0.5672.63-1~deb11u1_arm64-buildd.buildinfo b2cb7972bc07bb1b33840b53e5ea5ce2de7ca71b 60671916 chromium_113.0.5672.63-1~deb11u1_arm64.deb Checksums-Sha256: 1f7cad92261cad25488c1b42e1668dbf301ae4be1b7d462caca54ada06a96d7b 1121404 chromium-common-dbgsym_113.0.5672.63-1~deb11u1_arm64.deb 1f8f0a4c5176e066d974a236c76d28510c9a33fed8981537c46741168fd05f61 4807532 chromium-common_113.0.5672.63-1~deb11u1_arm64.deb b417dfadee72aeb993431c84f2064f735d90ba7c78b5dc4781e7fc278ef2767b 27195816 chromium-dbgsym_113.0.5672.63-1~deb11u1_arm64.deb 802efdadd034c3c48fd7408b4d4af054801c9aa46f72fd6d9469b487d64aeea4 5093308 chromium-driver_113.0.5672.63-1~deb11u1_arm64.deb e4d77bc2af814031910e20ef11c67a4f1b7fce3a4035091424676695acb2f2cd 12352 chromium-sandbox-dbgsym_113.0.5672.63-1~deb11u1_arm64.deb 71a3ba9034b615c3735a753b32f9361332de1839c777d2f8f4319e9479e33ef0 132956 chromium-sandbox_113.0.5672.63-1~deb11u1_arm64.deb 208f4fcc42b16c88f3c3e727081bdcab41845985b97fb0c72747d147ed54f64d 22546624 chromium-shell-dbgsym_113.0.5672.63-1~deb11u1_arm64.deb 08d9c8f4d6a0102523b9f3e3af59cb0b5c8e6772a98ec5303791e9e11a38ce3a 42472780 chromium-shell_113.0.5672.63-1~deb11u1_arm64.deb 383a0e1be9a5cf9b46ae1a02695d9f3b442970dff70ec1ed8e51eea4b3945d0f 25508 chromium_113.0.5672.63-1~deb11u1_arm64-buildd.buildinfo 07b49a0f8161aa82ebe9b54ba8dfb3e9f85fe0a27047abd10fc47afef10eff28 60671916 chromium_113.0.5672.63-1~deb11u1_arm64.deb Files: 0b874488c6dcfa21bae32286562974ee 1121404 debug optional chromium-common-dbgsym_113.0.5672.63-1~deb11u1_arm64.deb 4cd29a983e90e25f34c43594aa2647bd 4807532 web optional chromium-common_113.0.5672.63-1~deb11u1_arm64.deb df901691de5438fcb0b44e1646b94a70 27195816 debug optional chromium-dbgsym_113.0.5672.63-1~deb11u1_arm64.deb 7ad57c6e3467bc4e4ae0ddc0d7825609 5093308 web optional chromium-driver_113.0.5672.63-1~deb11u1_arm64.deb 9d29f75f7efdbe8e6e33338788f35a69 12352 debug optional chromium-sandbox-dbgsym_113.0.5672.63-1~deb11u1_arm64.deb 06a0af55af9ec7f379f8aeed264134ab 132956 web optional chromium-sandbox_113.0.5672.63-1~deb11u1_arm64.deb 472824664aa5643033345c927612042e 22546624 debug optional chromium-shell-dbgsym_113.0.5672.63-1~deb11u1_arm64.deb 7fa0a96cf29673aa85b6f92045796006 42472780 web optional chromium-shell_113.0.5672.63-1~deb11u1_arm64.deb 2a8db9631a781dc762d54fffbb3cb7cb 25508 web optional chromium_113.0.5672.63-1~deb11u1_arm64-buildd.buildinfo 154fdeb8b9871698d60df479ba74e930 60671916 web optional chromium_113.0.5672.63-1~deb11u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEUCZhpX7EW6FhRngRD7xMY/mIqXMFAmRVIRUACgkQD7xMY/mI qXPCqQ//eASzRgkftL7tIvTlTE6tDuAwb+7bvuV626SIavKBtmI/96CjK5nT17tV FRDh8NvIaqCl8ae2E4MlDFCTW0TbIWIXu7uFwTBT6odPHJrpIaDW6WrXtEpHr3A+ PSW4vxcGhYClqY09RvxTcgcNrMUdplpdbGHIYd1J95i3VThjqTvAx10KZin2H3+c z/TYzdymCH3163VpaxwoHBnMMh/K3olYHBKFtH5cj4FnxvBvkCVtdBT3HA9HhP2w 9rUIDhH8l+eW5tEQ6XcfOORjTNHDvz/mog/7/7LlHHrAemfIKji9/8FlBR7KmqhU MaI2edlM0QPnrkzVDlCAEo3tI9rqfCCvyh4Eucr/UZQPecBw43nUaBb6CYWX4+U1 RNcSTut/fJtXJc1XXapGVHLAyg12L60mk5HpJvJjjGoXDw4TZN3QPYJ23rA09E1m qPyssABnyuOhOgUAdn8COw6sjhduyi0hF7CPETXdAL9svydEq6rEVdJROb3MtoPo 05obSyh0ckb7rCpw7Nwf0qow1zxkR3HGnmzNj8AFyxnYP/7kUVA+z6gqtl6p9Kep FLUbnqQctizPP7laxpwInHLKKPkK0zQNYNQeSy3V+LbWQ96qo6X/bjR7BiLP2SFR Nv2KOE0m9KFh/Rr//VznPrNY7TnHajforpG9UnCyL1RgMNucW9Q= =auvf -----END PGP SIGNATURE-----