-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 09 Jun 2019 18:59:50 +0000 Source: chromium Architecture: source Version: 75.0.3770.80-1 Distribution: unstable Urgency: medium Maintainer: Debian Chromium Team <chromium@packages.debian.org> Changed-By: Michael Gilbert <mgilbert@debian.org> Changes: chromium (75.0.3770.80-1) unstable; urgency=medium . * New upstream stable release. - CVE-2019-5824: Parameter passing error in media player. Reported by leecraso and Guang Gong - CVE-2019-5825: Out-of-bounds write in V8. Reported by Gengming Liu, Jianyu Chen, Zhen Feng, and Jessica Liu - CVE-2019-5826: Use-after-free in IndexedDB. Reported by Gengming Liu, Jianyu Chen, Zhen Feng, and Jessica Liu - CVE-2019-5827: Out-of-bounds access issue in SQLite. Reported by mlfbrown - CVE-2019-5828: Use after free in ServiceWorker. Reported by leecraso and Guang Gong - CVE-2019-5829: Use after free in Download Manager. Reported by Lucas Pinheiro - CVE-2019-5830: Incorrectly credentialed requests in CORS. Reported by Andrew Krasichkov - CVE-2019-5831: Incorrect map processing in V8. Reported by yngwei - CVE-2019-5832: Incorrect CORS handling in XHR. Reported by Sergey Shekyan - CVE-2019-5833: Inconsistent security UI placement. Reported by Khalil Zhani - CVE-2019-5834: URL spoof in Omnibox on iOS. Reported by Khalil Zhani - CVE-2019-5835: Out of bounds read in Swiftshader. Reported by Wenxiang Qian - CVE-2019-5836: Heap buffer overflow in Angle. Reported by Omair - CVE-2019-5837: Cross-origin resources size disclosure in Appcache. Reported by Adam Iwaniuk - CVE-2019-5838: Overly permissive tab access in Extensions. Reported by David Erceg - CVE-2019-5839: Incorrect handling of certain code points in Blink. Reported by Masato Kinugawa - CVE-2019-5840: Popup blocker bypass. Reported by Eliya Stein and Jerome Dangu Checksums-Sha1: 8df4a7b6e2e13c81169e9d799ab9e11b63506901 4203 chromium_75.0.3770.80-1.dsc 2117269ffda465143689bd713ee494fdc38db6de 249930912 chromium_75.0.3770.80.orig.tar.xz 191722a31ee913339eccfc7ad383a2b859cfa9bd 189156 chromium_75.0.3770.80-1.debian.tar.xz 0b04b8a635a1efd4d4040257f132aba22ac4024b 21220 chromium_75.0.3770.80-1_source.buildinfo Checksums-Sha256: 607748db27ecc0efb39d3c4ea998e3c49b7b61eaff64ad18b252d7bf87449e3d 4203 chromium_75.0.3770.80-1.dsc a90bb8fc1775e39a466651301f827bbc0800296bde7b8498bdc852033efbc176 249930912 chromium_75.0.3770.80.orig.tar.xz 362f577cacbd644c421f4d68cee1db38f2d852ab7cf68d0c431581bae4ef0839 189156 chromium_75.0.3770.80-1.debian.tar.xz cbfa4571df15a33b7e250e49f47b4f09939e0bc03801fb08fcc1b09e10a5b8e8 21220 chromium_75.0.3770.80-1_source.buildinfo Files: c1b77f2bd008af095a368712a7b239cd 4203 web optional chromium_75.0.3770.80-1.dsc e7a35d64d0e06f5a5de9e54821e993d6 249930912 web optional chromium_75.0.3770.80.orig.tar.xz 051ef354b788715ecdbc3f460c0a64a0 189156 web optional chromium_75.0.3770.80-1.debian.tar.xz fdb2f1fc051cc29eadc772ce5646ab47 21220 web optional chromium_75.0.3770.80-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQQzBAEBCgAdFiEEluhy7ASCBulP9FUWuNayzQLW9HMFAlz9uVYACgkQuNayzQLW 9HM9sR/+IknKZxHfIGkRTs8dDL/+wrFvjWdRNGDH6WXElcURygXPHm/kMLfrypBV JSni6u0n68Qrg8tgf8eMhgJ++G35/PGQq8aLpE7i3Rn4pdyF5EHlsrudWkmrcpM+ 2nYow30fpfxPL6RtyzWc7T56Dgu6Fi+K3w0t9Sp8zD2A5c4ZCq2Y+75dOFJw4z6Y XsisjFb7eEOKF43v8mZseTyhUOLCgizlyV7XAD39vHF9C7RQS1U7OChdUoQy4rvH j9YiNK3EilPTrp5/RNYC/9xPD8fA1aWLcjY95lYb+rlwXZmz9r0IG90smA1jZFCD qQF8BBBO8cLJ6xMh2yIrRicIm19QsVerOMNw1eLZTZ+spPnjkyMW0y2O451f2ZPo mr2srN1p66pfjNjq3PZUePCsXrue7pWDImQrxW+8ViqzJVSq9Tmyeooh65KJgIe9 EAj89th3tLs1tHKlSZWlho7gxkNf9f4BDFStz99E9u3mh7oAC6FeMCWmDi9bNix0 Wqt4LWUSW8wKHdEULcWP8Wurp20I71V6g4T406HJEv4IrgHbX7el5btZcyn6jn/C 96onYNBOO3POqVa8ub4cZvMwCVxNO3SowVSPZBL7ZCWWhXUMqp48cKv+487covvg sJMDrB3SRW6tlCHqvHdh9MYIzcEDOIGJ5oNP1VY2GQc2scrXDPRLFhoND5pwzgbO A0wFFZXo6p9XG/wlDuPIINcs4bkyypVDCEULUKqH87kKyrZN2nSObUrzKhtKcgI0 NHLJJHUa9UgAbUZqI09MnrnybZgS/1N1CbPrfh1e0/hP3IDbReJxdPo3KxfHlNLn Kp/0slCpt5PcKO8bOHUsMxZtp5PRjF1tpTb2c99diP9ZlLcXyuph5dQNBc53mCNq CdZSGMH7ZtQf3XvUx3bJLqKVKH3bnfvdHVcEB2WkwsNQ1JfQspl662Uckb9CjeoC DYzKiazgqnGNQ10SDXsWb3viH8cWWXYMlwSmuT+TyPy0Bh+nsnYaO+aMAQQm3m7R uO+3k62kYBDJfKObUcxtGorZxai7JvLF95tgSNr4Bz9DrpIhkeNWsXq7ay090Hkh fvZcKdNsJo+OOBv/dLu+ZGLqBf2lA4Jp4S1cgL8OqZcsi6pz4bh1K0fiU+dAUzMK 7W6AvfWiCGZIlShfID/J87StWIwKE3g2/IKXmACfoGHBr3thdcW0yq+YZLFuQtUq As+G/hPZDrFMFLZS65VD/oRJfcuTHQnudFSVqY8lLLn7PnqxKa2UMLDlHaJ8gJRW GyCYLshRkZOnuiplT+doS31L+hxMXEDJROOt/qxnqF6MM2x6nRkYmNEFjdUEzT8S HwTpWOahuL9hAYNYgtm+yblceUnlpQ== =P0Rk -----END PGP SIGNATURE-----