-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 12 Jul 2013 15:19:18 +0000 Source: chromium-browser Binary: chromium-browser chromium-browser-dbg chromium-browser-l10n chromium-browser-inspector chromium chromium-dbg chromium-l10n chromium-inspector Architecture: source all amd64 Version: 28.0.1500.71-1 Distribution: unstable Urgency: medium Maintainer: Debian Chromium Maintainers <pkg-chromium-ma...@lists.alioth.debian.org> Changed-By: Michael Gilbert <mgilb...@debian.org> Description: chromium - Google's open source chromium web browser chromium-browser - Chromium browser - transitional dummy package chromium-browser-dbg - chromium-browser debug symbols transitional dummy package chromium-browser-inspector - page inspector for the chromium-browser - transitional dummy pack chromium-browser-l10n - chromium-browser language packages - transitional dummy package chromium-dbg - Debugging symbols for the chromium web browser chromium-inspector - page inspector for the chromium browser chromium-l10n - chromium-browser language packages Changes: chromium-browser (28.0.1500.71-1) unstable; urgency=medium . [ Michael Gilbert ] * New upstream stable release: - Low CVE-2013-2867: Block pop-unders in various scenarios. - High CVE-2013-2879: Confusion setting up sign-in and sync. Credit to Andrey Labunets. - Medium CVE-2013-2868: Incorrect sync of NPAPI extension component. Credit to Andrey Labunets. - Medium CVE-2013-2869: Out-of-bounds read in JPEG2000 handling. Credit to Felix Groebert of Google Security Team. - Critical CVE-2013-2870: Use-after-free with network sockets. Credit to Collin Payne. - Medium CVE-2013-2853: Man-in-the-middle attack against HTTP in SSL. Credit to Antoine Delignat-Lavaud and Karthikeyan Bhargavan from Prosecco at INRIA Paris. - High CVE-2013-2871: Use-after-free in input handling. Credit to miaubiz. - High CVE-2013-2873: Use-after-free in resource loading. Credit to miaubiz. - Medium CVE-2013-2875: Out-of-bounds-read in SVG. Credit to miaubiz. - Medium CVE-2013-2876: Extensions permissions confusion with interstitials. Credit to Dev Akhawe. - Low CVE-2013-2877: Out-of-bounds read in XML parsing. Credit to Aki Helin of OUSPG. - None: Remove the “viewsource” attribute on iframes. Credit to Collin Jackson. - Medium CVE-2013-2878: Out-of-bounds read in text handling. Credit to Atte Kettunen of OUSPG. - High CVE-2013-2880: Various fixes from internal audits, fuzzing and other initiatives. Credit to Chrome 28 team. * Install mksnapshot. . [ Shawn Landden ] * Enable armhf. * Build with system libwebp when version >= 0.3.0. Checksums-Sha1: 5b8f80c6c0cf42954a321fce14eef48d293d395e 4326 chromium-browser_28.0.1500.71-1.dsc c6170bbe78f16f0ffb2a50870c01d9c52977d655 1192403288 chromium-browser_28.0.1500.71.orig.tar.xz 358431dda02b5f698dc96190ad465fa32dbfa80f 258889 chromium-browser_28.0.1500.71-1.debian.tar.gz beb5bec58469f74c61e116f441c417cb2c386d11 161366 chromium-browser_28.0.1500.71-1_all.deb 3e36565c7108ce9c9b8c9555a7790406dc40e797 160698 chromium-browser-dbg_28.0.1500.71-1_all.deb d09cfb98ad6aea982fa7c725c69d411feac2c63b 160836 chromium-browser-l10n_28.0.1500.71-1_all.deb 8dcd9d3aa037537bb8e835a3d29d3610780c0364 160734 chromium-browser-inspector_28.0.1500.71-1_all.deb 7406602b0fe696b5758d82c6648621d6e4997557 2732110 chromium-l10n_28.0.1500.71-1_all.deb 3ee4be335437f7d31e4951f2ad18334f3b89037d 742610 chromium-inspector_28.0.1500.71-1_all.deb 811bbe16634f120667099326263785d2f3c80a42 44229758 chromium_28.0.1500.71-1_amd64.deb 719ebe9847c050a845569f906669531d836a7494 441683524 chromium-dbg_28.0.1500.71-1_amd64.deb Checksums-Sha256: 5d2148fd8cbfc4e427c5a3db047428d7e81401443b0b151a38737e22b7534bf6 4326 chromium-browser_28.0.1500.71-1.dsc 57c6ec7051a1b14f1c54883f18fc2f2ea624400d8e80b23c7c7375a21282aa6c 1192403288 chromium-browser_28.0.1500.71.orig.tar.xz 394c6d39792ace8b13487a2cf7594def7545a43a2caf5eeb4348a3b4472bc513 258889 chromium-browser_28.0.1500.71-1.debian.tar.gz 16fc55c2861183b2f2bfac16cc9ce8ccdd5be055b804922a029d9a72d5b02830 161366 chromium-browser_28.0.1500.71-1_all.deb 174e8b46e9162648d0e82e6796741ab3fc4a3ef2a0e4c8c3e1a4e9226a1b4d8c 160698 chromium-browser-dbg_28.0.1500.71-1_all.deb c3a4f8ff4b6f81e2c6b26da753851a677709f537e9d260d16504edff85b9bada 160836 chromium-browser-l10n_28.0.1500.71-1_all.deb 93cdfcc09bfdc061718a5125c2d1bad62df9ecbe42d832d6ae4495ddcf258161 160734 chromium-browser-inspector_28.0.1500.71-1_all.deb 5195bde2644b009806b7451d9ed3dcff0c0b5190b962b81f34c87d92729a793d 2732110 chromium-l10n_28.0.1500.71-1_all.deb 3ee3fc1e15de554b47347c54f8584345b3cb1536573b92e5f53553e343873e4a 742610 chromium-inspector_28.0.1500.71-1_all.deb 6aca74bfea4c3a71a2b9ac0f14967e8dd418bdae17b9746b8f6cadc49667fead 44229758 chromium_28.0.1500.71-1_amd64.deb 0b75b6b570fdfb512e7e9787dba08be7cfe49325d5ecf6b597c2bfa5f02d37bc 441683524 chromium-dbg_28.0.1500.71-1_amd64.deb Files: 10e8abab2d3317064744f6b19ff314a4 4326 web optional chromium-browser_28.0.1500.71-1.dsc bccc8f73b95603a1b6c3fb4f55671f28 1192403288 web optional chromium-browser_28.0.1500.71.orig.tar.xz 5c769fd21eec0871d0d25b1fd2174652 258889 web optional chromium-browser_28.0.1500.71-1.debian.tar.gz 239df48b1a16c1801ad835d5f166aa95 161366 oldlibs optional chromium-browser_28.0.1500.71-1_all.deb 53db4e76f89f7f0f18c27d339c2f12fd 160698 oldlibs extra chromium-browser-dbg_28.0.1500.71-1_all.deb c596316dba0f83fdc596d3bd1ef1422b 160836 oldlibs optional chromium-browser-l10n_28.0.1500.71-1_all.deb abe6323abbe88861f4f8adfd921c1924 160734 oldlibs optional chromium-browser-inspector_28.0.1500.71-1_all.deb 39008ee9a00c9d73622043fdbcc48864 2732110 web optional chromium-l10n_28.0.1500.71-1_all.deb 067366bfb201e80dbc9549577516d53d 742610 web optional chromium-inspector_28.0.1500.71-1_all.deb 58d8bc846579dfe9b7c1713f97fb0cf9 44229758 web optional chromium_28.0.1500.71-1_amd64.deb 45b21f90d25cfd2b9c93569331428535 441683524 debug extra chromium-dbg_28.0.1500.71-1_amd64.deb
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQQcBAEBCgAGBQJR4zaKAAoJELjWss0C1vRzeG4f/1mGDaBMYwL3ovMXjAnRzI6R 3UvuUtVVPDapRKBsJInn3CCEmfHkLzxuaxq0Pzz95WDETqYTFOSaHE2jrIphlDH3 esTK/I0LCIUEtN/SMn16/idhTBEXNVjnoUSAceQBJoi4tTzABm2nyRvyPpBU7msh MLQrKongNvBUgN6xMmVgEOQZqahhlftSJPA/tZnyaEwS+owbHz5xqYRfOktMr3n5 S00dSDUQqBjVUDkbhV5TTFSZi1OYZwOLKr1Mqp7cor8v26dzUHex4xQNFTJrqNS2 Knv1QEtjZzXtJBXpL8LhJZIB7PEj2m39s6tf+az58jHscqJQZe4TouPFtNtIC43q Q/MFfXSrTu7xWW28MNQ2HVl+JbSKKx2a5VGc3G5eqz0F020EbEYiVLT3w5B4dqMS VByPV/sDkAw8ousN1p/qMJxsyPUbD2gx2dVxBiXBjSy1BDozRl2ji7Zq8/+xFqtS IaPu+4Wmoa+tl0xR50+pcLplIQ/nQTKojxdFTqxwDgIxyPUrv/YHTmOXCC0jjK5c Pb09b/lFQ5ULn4pUsm1K1yRwMTngcyAhOVGhzD8aVSWuVCZYCWCjsi7V/Ujm3fEq a8QmJ2QXPigcZj08dPFodt4w1Z+0dhstJl7Guq7otJAmryagC63+GBlkWu54jxWn xvuSRjLSCwK5pJZN1SjBtvuqLuR0oURwYqgFTRQjKRvKDE3+M2z8WzZkF01VqZKv riLrrTFanutWaj0hE7HpP7BkRWoovPz0cDecHI/u0oM6kzBSVT4dfHCrlOHGlPAw tU/MtBlTHThn3HTQZrPk1D4krcyf09CY1bg5H5/tJQWDCwsJ8kJIVkDAKH/9zodP LSSYStJazWaonPSdSzIzTjTxweSBe2WrUcKiEmtJdW5qS8DUNFb5fKcQSIhKQ0o/ Tn530FrQFfJ0dclaLsv+VNk7usodsSzAQt4YG5OIWqTyQ7d6SvcahPlwOOkIGcZu +l2pRzhZCBLDtYFNisHysYRyBsjFxOHBidKT2mkOQNWVGMLOfY+MIt2aMYbBBYI0 eqW5aXN4NqlRiR1vhZWm0ORPYa42a0ZT579ObEThWDtwxl+HQULqk4PrCLv0UfGj dU1E+BXlN70BydZOuLdlanjEJrIQDquReK++PIKvMszXC+25UkuYpX9VuCjscDwS MxBK4wiJfeynTrnDFYqrwZZPRIUk0Dx4m2BIBlnl253BSm66hVRIo55gjk8H02Vo /nkIMmJcqnDlWUpus20H3EmBEw7WPz+fRo4KmR2ayM3k+okhyD/SJgQLm0V+4doR g+58hbZ953JkqxEi3tWgDfpv/6hWM08Ip7gNWaMsCtRYGwceR9kEpmsj8WwCMfo= =1x64 -----END PGP SIGNATURE----- -- To UNSUBSCRIBE, email to debian-devel-changes-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/e1uyxwy-0006j4...@franck.debian.org