-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 28 Sep 2023 00:41:20 -0400 Source: chromium Architecture: source Version: 117.0.5938.132-1 Distribution: unstable Urgency: high Maintainer: Debian Chromium Team <chromium@packages.debian.org> Changed-By: Andres Salomon <dilinger@debian.org> Changes: chromium (117.0.5938.132-1) unstable; urgency=high . * New upstream security release. - CVE-2023-5217: Heap buffer overflow in vp8 encoding in libvpx. Reported by Clément Lecigne of Google's Threat Analysis Group. - CVE-2023-5186: Use after free in Passwords. Reported by [pwn2car]. - CVE-2023-5187: Use after free in Extensions. Reported by Thomas Orlita. Checksums-Sha1: 40981af68c59231fef98db81fa8db5e5ce7efd0b 3695 chromium_117.0.5938.132-1.dsc a7a5223a74bb06881cfbd73f589734f927174235 683178832 chromium_117.0.5938.132.orig.tar.xz d5f0f21a6284c438c84a048891302d7af3ed66dc 385724 chromium_117.0.5938.132-1.debian.tar.xz 0ecefc382a78e6eaa0d0793c43cfc92fa656c74a 21098 chromium_117.0.5938.132-1_source.buildinfo Checksums-Sha256: c52c7419f8b268b436317d44635ba97702659b7a00f6ec99dd69ba0737d7de55 3695 chromium_117.0.5938.132-1.dsc f228b6a8abfbe134cd1cc03dd6057645851eb734fd17f38144c17996bd111fe2 683178832 chromium_117.0.5938.132.orig.tar.xz 0ffe60d1553f54f145932e9f6b612f85bca91b935cd8c6b677e491703fe94136 385724 chromium_117.0.5938.132-1.debian.tar.xz 90cfbec119fcd01e588372eff0522c2a0145f51375bcddf7054352b8f68bf89b 21098 chromium_117.0.5938.132-1_source.buildinfo Files: a6bb7a95a808949029d4cc3286bab144 3695 web optional chromium_117.0.5938.132-1.dsc 97cedd66275ca38733a33ffd4233936c 683178832 web optional chromium_117.0.5938.132.orig.tar.xz 5d868d08ceed006646d26f2c6d343f6a 385724 web optional chromium_117.0.5938.132-1.debian.tar.xz f14fb54f831297ecbd36c06a89ba5f57 21098 web optional chromium_117.0.5938.132-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmUVJmgUHGRpbGluZ2Vy QGRlYmlhbi5vcmcACgkQZF0CR8NudjcL7hAAtaI8dS0ll94s5qjNlFiR6teldiV/ 7s0iPB2VfjAr5vBe2mSFaD+lZMVmG/UgrS/Ra9754uF+gXhrHF/sEgiGvybuyI0A PZyG1n1GzPWtoXxzllqU4M6BnHc4aKAT+N3i2YOpl5hWeMT7Lk14+P8GPb+v/WgE AyAU9VXauNo3IvHYRtJNxRuHGL3xhMNBypskuRbqKssV3LzB419AtUV4NY3aDyGW WF/BeEfgCKPQff/tdpByRrlapWk8llxSJh7ri5tpvHNwhh+gPwjGzmFIWSMs0muM 21fIonS5LrFei26pnjsth7vM/Fwc4WSjOI+H21AlNooGVw/V4hgsy7ad5Px9JUyL Wykr4PXYmK1DdDdnDJRoBtMwwlMrZsvjRTjPgKSOenDTxR4ahDzkX2api6TDjM3j fsq0Jbs90aaGo7iuUrq6OwILinmt5GiLO0EhypmGU7ytvwmhpXSTv9pQSqbS/5ir 5dBB8k+JrfMTDF1NKNRAij5hKfczLHzxtdpujQRPqnWFJQBuo4CMruf01WMYj1vJ +fpzomZZQkZQcsLiE+SC8hZnJd/HxxFIFpGtpV8nYwBJ+k3tXPkZWe4qqkt9tA15 QdqiUvaXIgVtIWDPcHsMImdwlP5QULUKuuZ/Kl4sFcPetDFBZbMA09a8vCrflJjL tIdF2PcAdYel0Xo= =2fO6 -----END PGP SIGNATURE-----