-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 03 May 2023 00:42:00 -0500 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: armhf Version: 113.0.5672.63-1~deb11u1 Distribution: bullseye-security Urgency: high Maintainer: arm Build Daemon (arm-arm-04) Changed-By: Timothy Pearson Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Closes: 992178 1031352 Changes: chromium (113.0.5672.63-1~deb11u1) bullseye-security; urgency=high . * New upstream stable release. - CVE-2023-2459: Inappropriate implementation in Prompts. Reported by Rong Jian of VRI. - CVE-2023-2460: Insufficient validation of untrusted input in Extensions. Reported by Martin Bajanik, Fingerprint[.]com. - CVE-2023-2461: Use after free in OS Inputs. Reported by @ginggilBesel. - CVE-2023-2462: Inappropriate implementation in Prompts. Reported by Alesandro Ortiz. - CVE-2023-2463: Inappropriate implementation in Full Screen Mode. Reported by Irvan Kurniawan (sourc7). - CVE-2023-2464: Inappropriate implementation in PictureInPicture. Reported by Thomas Orlita. - CVE-2023-2465: Inappropriate implementation in CORS. Reported by @kunte_ctf. - CVE-2023-2466: Inappropriate implementation in Prompts. Reported by Jasper Rebane (popstonia). - CVE-2023-2467: Inappropriate implementation in Prompts. Reported by Thomas Orlita. - CVE-2023-2468: Inappropriate implementation in PictureInPicture. Reported by Alesandro Ortiz. . [ Andres Salomon] * Remove Michel from Uploaders. * Build against libopenh264-dev (closes: #1031352). * d/copyright: - drop fuchsia*: entirely different OS. - drop chrome/build: 200MB of PGO optimizations for official chrome builds. - drop third_party/updater: upstream included update binary. - re-add part of chrome/browser/resources/chromeos/ and chrome/android/ to fix build errors. * d/patches: - debianization/master-preferences.patch: check for initial_preferences or master_preferences, rather than just for the latter (closes: #992178). - disable/unrar.patch: complete rewrite for upstream's nested archive changes. - disable/catapult.patch: refresh. - upstream/webview-cstr.patch: add simple build fix from upstream. - upstream/monostate.patch: add simple build fix from upstream. - bookworm/clang-attribs.patch: build fix for clang-14 to keep from generating hundreds of warnings per compilation unit. - bookworm/typename.patch: add another build fix for missing typename. - bookworm/lamba-bug.patch: add to work around compiler bug (clang < 16). - bullseye/constexpr.patch: work around build failure w/ bullseye's clang/libstdc++. - disable/openh264.patch -> bullseye/openh264.patch, and stop using it for sid & bookworm. - bullseye/disable-mojo-ipcz.patch: refresh. - bullseye/mulodic.patch: refresh. . [ Timothy Pearson ] * d/patches: - Set baseline ppc64 CPU to POWER ISA 3.0 (OpenPOWER, POWER9) - Enable VSX acceleration in Skia - Refresh ppc64le/third_party/0002-third_party-libvpx-Remove-bad-ppc64-config.patch - Add fixes for new Highway library on ppc64 - Suppress harmless warning messages from compiler during ppc64 builds Checksums-Sha1: 2fb280e27fffde36d92dd3c790703e8b3299d623 1141856 chromium-common-dbgsym_113.0.5672.63-1~deb11u1_armhf.deb df05be7ecb769f8ffbb44ff214734025dceb0473 4899136 chromium-common_113.0.5672.63-1~deb11u1_armhf.deb 92623e506d8227d3cc8b4ac4cbe73c6c513ef53b 26759196 chromium-dbgsym_113.0.5672.63-1~deb11u1_armhf.deb 587249fcbe7b50d32da9248dd8cf16a2081153a1 5749536 chromium-driver_113.0.5672.63-1~deb11u1_armhf.deb d51c7e25eb5ba08046a23e63000ff4b6c8df01f9 11160 chromium-sandbox-dbgsym_113.0.5672.63-1~deb11u1_armhf.deb 1bffa4d2c2fb2b5b1b55e0f70e9b221a45af0881 132656 chromium-sandbox_113.0.5672.63-1~deb11u1_armhf.deb 55c07554e6986f51125309aff38dec9447df5672 21719928 chromium-shell-dbgsym_113.0.5672.63-1~deb11u1_armhf.deb 3607b96fec6344f71ec3a810d7be7eae507b042e 43456200 chromium-shell_113.0.5672.63-1~deb11u1_armhf.deb 13353438cc6898a45bca9c3841dd22e6d6c5d55d 25499 chromium_113.0.5672.63-1~deb11u1_armhf-buildd.buildinfo 7e239e97538da51a14d00eabf44c49dea4bc8a1d 62516212 chromium_113.0.5672.63-1~deb11u1_armhf.deb Checksums-Sha256: 403069dbb3f9fcd4dc269710492458a10db0086be351f546c41859082370300f 1141856 chromium-common-dbgsym_113.0.5672.63-1~deb11u1_armhf.deb a11896d249a6a2da70e485e72ac57b90566a18ca3594518a7763d44ee254fb21 4899136 chromium-common_113.0.5672.63-1~deb11u1_armhf.deb 2ca2eb4c92aa6736abd1abe8ee4815f86999b5f8fb9f2fdfb685644872a3b4f5 26759196 chromium-dbgsym_113.0.5672.63-1~deb11u1_armhf.deb 4bdb857153d1f8ce01c03b17f705c7af49a25ecc8064c3587a7188fdcf06e4ea 5749536 chromium-driver_113.0.5672.63-1~deb11u1_armhf.deb daf980a7317219960f1f0cdc494cf6fd41bdf0b6dc15cd17bf11f1b0fd92bc74 11160 chromium-sandbox-dbgsym_113.0.5672.63-1~deb11u1_armhf.deb f119ab16bafd5bcf06386bb70a055fdccb2c941cc85fc6159a3ae7f9f0746881 132656 chromium-sandbox_113.0.5672.63-1~deb11u1_armhf.deb b5ce9239a7d70d0793916254de8d7b4b455d517c3e5582f171feab8b2a385c74 21719928 chromium-shell-dbgsym_113.0.5672.63-1~deb11u1_armhf.deb 86fb0edba2852b01ca3fde033488d84ffcf8ffa43e9970135d03ae668fead064 43456200 chromium-shell_113.0.5672.63-1~deb11u1_armhf.deb 253f815064a972033a037633194efd4081aad210ff978f7e5e9ba9252d1f849a 25499 chromium_113.0.5672.63-1~deb11u1_armhf-buildd.buildinfo 4b282f2c272f658e6ac9203395301bd81fb3c2edd964fc362f5d3efd055b2ca9 62516212 chromium_113.0.5672.63-1~deb11u1_armhf.deb Files: fcf6ee4c5bc1abd4a03290018e88aa53 1141856 debug optional chromium-common-dbgsym_113.0.5672.63-1~deb11u1_armhf.deb 94cd50f1ae8e4e00a4fb9b6201a5ba59 4899136 web optional chromium-common_113.0.5672.63-1~deb11u1_armhf.deb 3370d7adadb1ad8b9fea78f419ea2fbd 26759196 debug optional chromium-dbgsym_113.0.5672.63-1~deb11u1_armhf.deb e8660875c8382dd0e8b83d00fbe0a2dd 5749536 web optional chromium-driver_113.0.5672.63-1~deb11u1_armhf.deb d5dafb8cf082299ba2bf973c89fb39d6 11160 debug optional chromium-sandbox-dbgsym_113.0.5672.63-1~deb11u1_armhf.deb c59c1707baee8766a27abcc32a3c87e3 132656 web optional chromium-sandbox_113.0.5672.63-1~deb11u1_armhf.deb 2c14490746a6337c1226ef02d3e222d4 21719928 debug optional chromium-shell-dbgsym_113.0.5672.63-1~deb11u1_armhf.deb 53aab06d9a62adb6786819451b8723e2 43456200 web optional chromium-shell_113.0.5672.63-1~deb11u1_armhf.deb b49abc7bd8de98f50d646273ee27e8d8 25499 web optional chromium_113.0.5672.63-1~deb11u1_armhf-buildd.buildinfo b8224f4d8b05e47418921c310b354530 62516212 web optional chromium_113.0.5672.63-1~deb11u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEmUDOxnfDwdc47jJKqoc2e3yvTA0FAmRS7ZIACgkQqoc2e3yv TA39sxAAkvnJhP/rzxjSkdlfn3MD2KuTvCZel5Z4oUJ2SuIStLGddGK6W91y7LZN RSnvieBg9Zp7D9KzeIiijkoSyayqRoHQGJoBzY1YYBXEtypF20pXV3GqFR0ib0mY XTsS4HOxPobJDcSR8t321JRYGA6mZcWk60H0YBLen7zW1w5NrB4WB3P4+2vw7Vqf POrM9ms55o3mYYbsJ/9rH1QFYTOOo1c1Z07BjmubgCrBzNqwavxWrKpPXVtgLDKq FzVkf729sv95BghfmIr/oWSSJNDlYWEtgtwWqv6/QvqHZI6Eff3HLwzlR5PTqUHU HieQk3c8AnMQzAQKo+wTEcP2LlSXvb341fQEnxlgmBTJuKyC82/XseZ73+wJVii2 jnYPI5hXK1pmbDEojJFs6PQhvmDBtj+pl3nfXE+9HGL6785zAxQAlKOnAaOmGhQ7 qMnHIOqvtxFyTlQjrPvhpZ5xOeh0dqgyrl2qKZgjcZM7EV6kYNfAtkhy9CLbN7dt x/SLTIm0eILLOCt/IYp9yKjPmHswZ9u9M54J/Y7pODS2MtHR11B6Het3xkU9XIFF SkRtd/Oy1tK36w93avEcPI7ka09AO5Z2YefNVBQ5gEXC6DyXj8KsRUmbWgfZpi5s 6szMkwwtTtr+xn+6b4Ixp5EnuN0KPBVImJRIc9Y0j6chuLF58AU= =qFjJ -----END PGP SIGNATURE-----