-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 08 Dec 2023 11:40:41 -0500 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: i386 Version: 120.0.6099.71-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-conova-02) Changed-By: Andres Salomon Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Changes: chromium (120.0.6099.71-1~deb12u1) bookworm-security; urgency=high . [ Andres Salomon ] * New upstream stable release. - CVE-2023-6508: Use after free in Media Stream. Reported by Cassidy Kim(@cassidy6564). - CVE-2023-6509: Use after free in Side Panel Search. Reported by Khalil Zhani. - CVE-2023-6510: Use after free in Media Capture. Reported by [pwn2car]. - CVE-2023-6511: Inappropriate implementation in Autofill. Reported by Ahmed ElMasry. - CVE-2023-6512: Inappropriate implementation in Web Browser UI. Reported by Om Apip. * d/copyright: adjust path for chai.js & mocha.js deletion. - delete third_party/libsecret. * d/control: new build depends on libsecret-1-dev. * d/scripts/unbundle: keep bundled libhwy; it's not available in bullseye. - also keep vulkan_memory_allocator and flatbuffers. * d/patches: - fixes/gcc13-headers.patch: refresh. - fixes/blink-frags.patch: drop part of patch & refresh. - disable/catapult.patch: refresh. - disable/driver-chrome-path.patch: update for minor upstream changes. - ungoogled/disable-privacy-sandbox.patch: update from ungoogled-chromium. - ungoogled/disable-web-environment-integrity.patch: update from from ungoogled-chromium. - upstream/mojo.patch: update patch from upstream's git. - bookworm/clang16.patch: new patch working around upstream's clang18 flags. - upstream/nullptr_t.patch: more libstdc++13 build fixes. - upstream/string-include.patch: add a simple header include build fix. - fixes/absl-optional.patch: add a workaround for a clang bug (https://github.com/llvm/llvm-project/issues/50248) by providing our own 'optional' header. - bookworm/constcountrycode.patch: add workaround for older libstdc++. . [ Timothy Pearson ] * d/patches/ppc64le: - third_party/0001-Add-PPC64-support-for-libdav1d.patch: refresh for upstream changes - third_party/0002-third_party-libvpx-Remove-bad-ppc64-config.patch: refresh for upstream changes - third_party/0003-third_party-ffmpeg-Add-ppc64-generated-config.patch: regenerate - third_party/skia-vsx-instructions.patch: refresh for upstream changes - third_party/use-sysconf-page-size-on-ppc64.patch: refresh for upstream changes - Mass refresh all other patches against 120 codebase. No functional change. Checksums-Sha1: 2598ef947b574b6f291d1b4009ecb88584855197 1156928 chromium-common-dbgsym_120.0.6099.71-1~deb12u1_i386.deb 6fdc8bac44f03ccf6656ce2e9e8d6cafd29f7125 4952860 chromium-common_120.0.6099.71-1~deb12u1_i386.deb 7c64f9d08c40f1270ff8878acfd070df0ded2753 31737968 chromium-dbgsym_120.0.6099.71-1~deb12u1_i386.deb 3a4ab65f0bd3b4fbb83dcca8fcfe0537dd81c21a 6133752 chromium-driver_120.0.6099.71-1~deb12u1_i386.deb 68b07282a9ee58de3af0dc7d0e45b2eca9cd9265 13960 chromium-sandbox-dbgsym_120.0.6099.71-1~deb12u1_i386.deb 279463a23004f41d73921b0da25413106fa5bf0b 84716 chromium-sandbox_120.0.6099.71-1~deb12u1_i386.deb 9232bc99cfb1f96dcd85b7984b647b6753c392fc 26972024 chromium-shell-dbgsym_120.0.6099.71-1~deb12u1_i386.deb b85aa01983c7f58dd356e12477ad1aa2ec6cd974 51088076 chromium-shell_120.0.6099.71-1~deb12u1_i386.deb f5d5cbece53988f283d78238306f071cdf0808ca 24441 chromium_120.0.6099.71-1~deb12u1_i386-buildd.buildinfo 5cf871ae5e238ba90827e777bcdfa84310770638 73691728 chromium_120.0.6099.71-1~deb12u1_i386.deb Checksums-Sha256: c520e0abf02766f22b2d5ea9d18e15973fa0fdab0132c32049d58a6a58a59bd9 1156928 chromium-common-dbgsym_120.0.6099.71-1~deb12u1_i386.deb cd68452cedd5cf86e5187cced51b6d87d67880efdd0fa0f9ba6c6fc2a2c7c273 4952860 chromium-common_120.0.6099.71-1~deb12u1_i386.deb e6aa807040cfcafb0174dfa49445f866a76e646550fffc063c542b6809c3e66d 31737968 chromium-dbgsym_120.0.6099.71-1~deb12u1_i386.deb 62eb38ef382231827b6a24bd20d74d8f888ad20b70333d3397389c5d984ff0fa 6133752 chromium-driver_120.0.6099.71-1~deb12u1_i386.deb a77ca7e9d0157079e9e3d00207f85a94ec0185a175b9c6ba4241d57f6ac390d1 13960 chromium-sandbox-dbgsym_120.0.6099.71-1~deb12u1_i386.deb a330c28e9a9b327d8d379a2558be24eaaa81a7f81f64948e847e4a7d3cd48f00 84716 chromium-sandbox_120.0.6099.71-1~deb12u1_i386.deb cff06ab3a3ff332a3d676814812e15412fc1b23aebaf7cb04ae64e23bccc0f8e 26972024 chromium-shell-dbgsym_120.0.6099.71-1~deb12u1_i386.deb 81b12a6e20237c1faf128a41de3ade4395e391c0bdad82c03a4e6d0f7099dbcd 51088076 chromium-shell_120.0.6099.71-1~deb12u1_i386.deb fb56df84e786b323378b7297821edd14c178ef49ed7ed87df22c3eab2f844afa 24441 chromium_120.0.6099.71-1~deb12u1_i386-buildd.buildinfo 01c6b3a4db780a430123ff34abded2764b791c965316d02efc112380b337d126 73691728 chromium_120.0.6099.71-1~deb12u1_i386.deb Files: e3a8b777456d107eb3e7c5507db45f1a 1156928 debug optional chromium-common-dbgsym_120.0.6099.71-1~deb12u1_i386.deb cd31752b25c1898a3549aa3153bd5def 4952860 web optional chromium-common_120.0.6099.71-1~deb12u1_i386.deb 45e2b379d1f89c2031ca93d29ed0b2ae 31737968 debug optional chromium-dbgsym_120.0.6099.71-1~deb12u1_i386.deb 4f22c59ca2a57a613f8c4efc4a474c20 6133752 web optional chromium-driver_120.0.6099.71-1~deb12u1_i386.deb f5233b7a03d50baa92d87e206f7da2f5 13960 debug optional chromium-sandbox-dbgsym_120.0.6099.71-1~deb12u1_i386.deb b96870620a1e9dca606de040cc71daff 84716 web optional chromium-sandbox_120.0.6099.71-1~deb12u1_i386.deb 5e488362df78855af3fa3386023068bf 26972024 debug optional chromium-shell-dbgsym_120.0.6099.71-1~deb12u1_i386.deb 57bcaa34ce16d24f4eed1154fb2f43fb 51088076 web optional chromium-shell_120.0.6099.71-1~deb12u1_i386.deb 1a9b538d0572392c13f41b7176dcb661 24441 web optional chromium_120.0.6099.71-1~deb12u1_i386-buildd.buildinfo 53a66577fef54e81fb9ad54286ddc024 73691728 web optional chromium_120.0.6099.71-1~deb12u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEOtJZa9Q/HRv7PgxxkF7E12VCox0FAmVz2/QACgkQkF7E12VC ox11tw//XbgFU6OYDIqzQsTLMLuSpo3LK77RWgISfpPDk9CAJt6y4paLZeoVoLpz 7fbd9fDeef/QM9EUHAuU34uyFU8FyTOiMCOPstE/ht649U9s0mMlBMI6RFtPEB9U cp/rpgUKTMWt7z9njWdTq8xrTvo612zXstJ2nBYYlzhVtTmIkKNuJO4OkssILag6 7SYQCyfBeIAPIss4St7G0mVtdaNkbsNa91kIMBWw66pYAC8Qj/2WIxnrpKEcIzN/ btzq2lE7YhRPUsizJSRpQg76B0uV5ZuvGZmGBnn3Fsz6kIQHq/OX4qisV/ZqwN0M F5YO/gyhVwr2nVRb4FRPMv/pxE8nJs9t+JZrvwSiiAb05+4DRAUvjrIZKKYERiem 6UfbDFgbShKc3z5VvcJZuO/2bIY0BuxOkyNvZurHbvGbcsJNllT4sGr6JCo31+MB GfiizeM3A7UU3Zx/0ozTyRYaSoB0ey+/KfDUtB9u8TDY6Vtfage2Nov4z5u1V2m+ 1DIahwN8edNo6PgRDNpFKRIjaTaqyoB/TYzZ9H9hP49UrmVmhFrU41HlkNS7EfBZ YP5dr/w7qi2+wzuJAei3qaoexAsFJGnsVayIw57Ck8t/ZSV1zcuJBw5ecTYjw4AA jt8fTNv93DxOsGrKqzAUVyKvTsbJmuZek9DK2EEn7pdYMyVeNs0= =1QeF -----END PGP SIGNATURE-----