-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 09 Nov 2022 19:57:34 -0500 Source: chromium Architecture: source Version: 107.0.5304.110-1~deb11u1 Distribution: bullseye-security Urgency: high Maintainer: Debian Chromium Team <chromium@packages.debian.org> Changed-By: Andres Salomon <dilinger@debian.org> Closes: 1015931 Changes: chromium (107.0.5304.110-1~deb11u1) bullseye-security; urgency=high . * New upstream security release. - CVE-2022-3885: Use after free in V8. Reported by gzobqq@. - CVE-2022-3886: Use after free in Speech Recognition. - CVE-2022-3887: Use after free in Web Workers. Reported by anonymous. - CVE-2022-3888: Use after free in WebCodecs. Reported by Peter Nemeth. - CVE-2022-3889: Type Confusion in V8. Reported by anonymous. - CVE-2022-3890: Heap buffer overflow in Crashpad. Reported by anonymous. * Clean up old crash dump files on launch (closes: #1015931). * debian/patches: - bullseye/mulodic.patch: (hopefully!) fix FTBFS on bullseye under i386 and armhf. Checksums-Sha1: edcce10e0427b3307979fb09f953cd453a144982 3808 chromium_107.0.5304.110-1~deb11u1.dsc 166fb70b4875f0faa0f72a8f6ab934a47dea524c 647729844 chromium_107.0.5304.110.orig.tar.xz 669541cb789dc294e61beae22c35ac7195dac339 290916 chromium_107.0.5304.110-1~deb11u1.debian.tar.xz 696ad42d94b3e8327d6977a319d28a314f88687e 21245 chromium_107.0.5304.110-1~deb11u1_source.buildinfo Checksums-Sha256: d605e66040d25b20d3464e0605fd299796298dee5940357b44b6fae3b74f36a6 3808 chromium_107.0.5304.110-1~deb11u1.dsc aa5e35d8a8096fa63fc4e8dc76a3f79105bdfff50ca95e5492fc9e6b6a669140 647729844 chromium_107.0.5304.110.orig.tar.xz 25154f7b9ac15786f4e11c9a698be7059fbac886645b97fef4a09cc94756144b 290916 chromium_107.0.5304.110-1~deb11u1.debian.tar.xz fec6f26e65f0fb376d20b5f7296dc7b83a5b3fef2b6e7373d7a1c68b5296c09c 21245 chromium_107.0.5304.110-1~deb11u1_source.buildinfo Files: a97922962c8e9b525570f0d5cb249286 3808 web optional chromium_107.0.5304.110-1~deb11u1.dsc ac849a82d5c01ed5198841f39e9e3d56 647729844 web optional chromium_107.0.5304.110.orig.tar.xz 0c7eca7201a98cefcfa50bf283465750 290916 web optional chromium_107.0.5304.110-1~deb11u1.debian.tar.xz 42a7c7d7e2de36e27e8c12aa70a0636c 21245 web optional chromium_107.0.5304.110-1~deb11u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmNs0+QUHGRpbGluZ2Vy QGRlYmlhbi5vcmcACgkQZF0CR8Nudjc6NRAAigl8L0cxySOFzD5IPcc9muvm2afr vVL/S1DAg+9b7AduUFf2kgFtX1Oj9MMFDkvWimhl+7LLl7nURwzFEIFntv+zY+SR R0jCs+PXsEbBlWRCSHfX4DcRIK54CotlhwX9JHOGucoWfYmpSgFVfCCLG8rIpsKw lQT7J0oJBAD+ETRf0QRuEfNnqZNS1A2/higtMDkFDtbE5h1OvR5nLuSoNFaaJDZ7 fFWUBRsv6WkQL1ENz0tyBhXFcvtrF8DkbgiugzhYRYKJ0kE2r/cBn8HRtcGH3s84 eXQIELHsy0c1lN/k6dRQOFR5J0Fi8d13tqEsO69AFJ2rNR1Je4Xu7HpVayOVDjdH owpKo7XHjl4N7lqWvMd+FqkWiq+HJTHdfZbB3aLVf+bHz9y/4ENSnPr6YheFDyfq JDz937jsTv+I0U99QvTjB41MDu7qlRPHHntWjSgwEt7QPEk4PmiqT7a3maEzf3bg EoDeYJaOHKZB/Yps2ERn8+F+vXO3C2cbBKfuB9Fa+tVU9uy2WH+9Wf2NL6Od88Uv K+MX5alwh6OCcr2UFll0pMSajveFKBfRevzNV12EqxgkD746lU8w72Lcl5K49ZyI FULp535us/U5c4UfY6H6u4uUsNyk+SBTjZ4PUTv3i2t5dwrpH03gX8nh35ky8sUU WhQRvtwCSv0OqdY= =DU9g -----END PGP SIGNATURE-----