-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 03 May 2023 00:42:00 -0500 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: i386 Version: 113.0.5672.63-1~deb11u1 Distribution: bullseye-security Urgency: high Maintainer: amd64 / i386 Build Daemon (x86-ubc-02) Changed-By: Timothy Pearson Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Closes: 992178 1031352 Changes: chromium (113.0.5672.63-1~deb11u1) bullseye-security; urgency=high . * New upstream stable release. - CVE-2023-2459: Inappropriate implementation in Prompts. Reported by Rong Jian of VRI. - CVE-2023-2460: Insufficient validation of untrusted input in Extensions. Reported by Martin Bajanik, Fingerprint[.]com. - CVE-2023-2461: Use after free in OS Inputs. Reported by @ginggilBesel. - CVE-2023-2462: Inappropriate implementation in Prompts. Reported by Alesandro Ortiz. - CVE-2023-2463: Inappropriate implementation in Full Screen Mode. Reported by Irvan Kurniawan (sourc7). - CVE-2023-2464: Inappropriate implementation in PictureInPicture. Reported by Thomas Orlita. - CVE-2023-2465: Inappropriate implementation in CORS. Reported by @kunte_ctf. - CVE-2023-2466: Inappropriate implementation in Prompts. Reported by Jasper Rebane (popstonia). - CVE-2023-2467: Inappropriate implementation in Prompts. Reported by Thomas Orlita. - CVE-2023-2468: Inappropriate implementation in PictureInPicture. Reported by Alesandro Ortiz. . [ Andres Salomon] * Remove Michel from Uploaders. * Build against libopenh264-dev (closes: #1031352). * d/copyright: - drop fuchsia*: entirely different OS. - drop chrome/build: 200MB of PGO optimizations for official chrome builds. - drop third_party/updater: upstream included update binary. - re-add part of chrome/browser/resources/chromeos/ and chrome/android/ to fix build errors. * d/patches: - debianization/master-preferences.patch: check for initial_preferences or master_preferences, rather than just for the latter (closes: #992178). - disable/unrar.patch: complete rewrite for upstream's nested archive changes. - disable/catapult.patch: refresh. - upstream/webview-cstr.patch: add simple build fix from upstream. - upstream/monostate.patch: add simple build fix from upstream. - bookworm/clang-attribs.patch: build fix for clang-14 to keep from generating hundreds of warnings per compilation unit. - bookworm/typename.patch: add another build fix for missing typename. - bookworm/lamba-bug.patch: add to work around compiler bug (clang < 16). - bullseye/constexpr.patch: work around build failure w/ bullseye's clang/libstdc++. - disable/openh264.patch -> bullseye/openh264.patch, and stop using it for sid & bookworm. - bullseye/disable-mojo-ipcz.patch: refresh. - bullseye/mulodic.patch: refresh. . [ Timothy Pearson ] * d/patches: - Set baseline ppc64 CPU to POWER ISA 3.0 (OpenPOWER, POWER9) - Enable VSX acceleration in Skia - Refresh ppc64le/third_party/0002-third_party-libvpx-Remove-bad-ppc64-config.patch - Add fixes for new Highway library on ppc64 - Suppress harmless warning messages from compiler during ppc64 builds Checksums-Sha1: 1a8a2d622dfe0862d10481b2b501b5466ab89637 1026968 chromium-common-dbgsym_113.0.5672.63-1~deb11u1_i386.deb 698f1f40f10754f057eacc844afd9b5a801826b6 4899348 chromium-common_113.0.5672.63-1~deb11u1_i386.deb 6c7116ae88918f28c1f65f56b56a57f718f79df0 28292416 chromium-dbgsym_113.0.5672.63-1~deb11u1_i386.deb eb59c6ade943ef5e89b97a7d0a8778539cf51e3b 6215380 chromium-driver_113.0.5672.63-1~deb11u1_i386.deb b4192381e5439889341be8d4375f876468475561 11680 chromium-sandbox-dbgsym_113.0.5672.63-1~deb11u1_i386.deb ed8459e8861cde3cbe0a6ff6dc8d88f89c5e1ad7 133036 chromium-sandbox_113.0.5672.63-1~deb11u1_i386.deb da6b539c11d05d65202b63378c288c5921f2dee0 24410632 chromium-shell-dbgsym_113.0.5672.63-1~deb11u1_i386.deb 8dda0d3da69f57f0144b1b20a08bac0ceee1e738 49052548 chromium-shell_113.0.5672.63-1~deb11u1_i386.deb 9ff8e83ab6c250e344a6196d7aadcd7da8255ac3 25555 chromium_113.0.5672.63-1~deb11u1_i386-buildd.buildinfo 083e70458e6f87d28df9993eb835a00f12582df8 69937632 chromium_113.0.5672.63-1~deb11u1_i386.deb Checksums-Sha256: 4c17a71e3dd4fb123eed9137814a30fc404caba33b6483baf5b3e2e1a4846c2c 1026968 chromium-common-dbgsym_113.0.5672.63-1~deb11u1_i386.deb 5be43a3999c08d4940817fc0cd6dd5de23921fb3c89100b29a93db43c039b0da 4899348 chromium-common_113.0.5672.63-1~deb11u1_i386.deb d25956430f31678bd98711a2346c4c4a7e0108b6df2bfad604746ac2b8e81af3 28292416 chromium-dbgsym_113.0.5672.63-1~deb11u1_i386.deb f51eee2b6cbe1a13e8cbf719840c67856725c1c459b8748401207dc524d7e714 6215380 chromium-driver_113.0.5672.63-1~deb11u1_i386.deb 365de7c317183e69d695c656885e984d69ab1df129a110a43aaa73418bc86dd9 11680 chromium-sandbox-dbgsym_113.0.5672.63-1~deb11u1_i386.deb e5bda9d52753cbacb112bffcab0751b5c3590474f44a685c68c5295eeef311e4 133036 chromium-sandbox_113.0.5672.63-1~deb11u1_i386.deb f67b8979faf2e5359d927f2cf9d38b90f21919753966a9145218221b99cf2771 24410632 chromium-shell-dbgsym_113.0.5672.63-1~deb11u1_i386.deb 15760f2790a8bac0e33a605d53b622250d24e03ee01fa156c822ce4fe4ea634d 49052548 chromium-shell_113.0.5672.63-1~deb11u1_i386.deb 1548a922d9094bacc676f6a8178d0bdeb111fa34582d57d32648eaefa6356f8b 25555 chromium_113.0.5672.63-1~deb11u1_i386-buildd.buildinfo 6e12e836a0a974c21d87372e511babe016864b4254b4234bc492ae407d82321f 69937632 chromium_113.0.5672.63-1~deb11u1_i386.deb Files: 943b3aab4c8610515d091f0335f6b52b 1026968 debug optional chromium-common-dbgsym_113.0.5672.63-1~deb11u1_i386.deb 9aadcd83fa46fd49d5a0ed420be69763 4899348 web optional chromium-common_113.0.5672.63-1~deb11u1_i386.deb 68c857c8838d624d408a8904f1a69a2e 28292416 debug optional chromium-dbgsym_113.0.5672.63-1~deb11u1_i386.deb 6a4dbd0d0be35499e0b4070e86c79ee4 6215380 web optional chromium-driver_113.0.5672.63-1~deb11u1_i386.deb f30318e0566dd8e61e56a318a585f189 11680 debug optional chromium-sandbox-dbgsym_113.0.5672.63-1~deb11u1_i386.deb 3a1dda498840050a0c03a400513ec9e3 133036 web optional chromium-sandbox_113.0.5672.63-1~deb11u1_i386.deb 0c1226bc2fd729b538c1b65a6f19ff60 24410632 debug optional chromium-shell-dbgsym_113.0.5672.63-1~deb11u1_i386.deb 00d8a488d67c202f2441fc881b4a5b61 49052548 web optional chromium-shell_113.0.5672.63-1~deb11u1_i386.deb d65672901d7ca76a3ed4c5729c783884 25555 web optional chromium_113.0.5672.63-1~deb11u1_i386-buildd.buildinfo 1325e813c121181b03ffe5b2b2eadae7 69937632 web optional chromium_113.0.5672.63-1~deb11u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEJyRdn7p9tGRfxctAots23/koc0EFAmRS+GYACgkQots23/ko c0Gcqg//dJn421JzNmjeS5xqZoRPnsMisxTyGLqVfAUK4nH6NulK4rIz0Vcj5lO1 DVRDymUCZoh2K6Pmd69zkni1P0vtSjLpIjwQj2/UDcyAkx7q+MZ5Uw6BS4CT9WGn FTyWsxuzikxtEsnvLVyOfALYZI2FpXIfEXi8VAx5dm0/icsQ1eDW6oLVbLm+A7mn 5vH8lvanyCTEMbSQysZDduQzQDBPmrH42roI6CdRSDXYhDeaiTLgwvHkRMHZMF1b /X8tIhIiA6Vwhz2TCjGSjf1Cwy2rNCRhJ1jYCTTEEgPA2Y/jcGmaodc+DUmp8GpV WgLwdWn7WMHC5sZ3TvPUdbn8OjbkxDrUJb1xEeQ+gT0pC+tGILeocUe0qi+KJH3T 0IRcWytW+H+AtW22LrPdesYW0MOiB1ffCkIoDVP3cmHV/TkRobSKZdxriQSavqqq BJfTT3J7vbxOKZXvqK8HT1HoPG88b69EBWo6MAXSq1A3Tj6sWwyT7QH9LBQqEZLS 2MY29AOCPROtG8a0ZDz71iMohmzbwjV4aDDD66NUbmyF/RrzNiC0ANz857+ZAfw6 d1um1uEBAsRquvsurf8Aj3XkwB8CZvdQhCCWZLMnkvSrIRgi1upVfPKM8uFWDNbA rlXVD29qFj6jgj1Xm02PGHi/mi6DI8aIFXQ/I/dRXpdmlg7f0uQ= =22eB -----END PGP SIGNATURE-----