-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 04 Sep 2024 09:51:21 -0400 Source: mozjs128 Built-For-Profiles: noudeb Architecture: source Version: 128.2.0-1 Distribution: unstable Urgency: high Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org> Changed-By: Jeremy Bícha <jbicha@ubuntu.com> Closes: 1079077 Changes: mozjs128 (128.2.0-1) unstable; urgency=high . [ Jeremy Bícha ] * New upstream release - CVE-2024-8381 Type confusion when looking up property names - CVE-2024-8382 Internal event interfaces exposed to web content - CVE-2024-8384 Garbage collection could mis-color cross-compartment objects - CVE-2024-8385 WASM type confusion involving ArrayTypes - CVE-2024-8387 Memory safety bugs . [ Simon McVittie ] * Add patch to fix detection of architectures that require -latomic (Closes: #1079077) Checksums-Sha1: c68e70a129f5e16f588b696c5938cb73afb3dfd5 2387 mozjs128_128.2.0-1.dsc c24352366f414514f7810cb8b9894a5af8496f4b 157072564 mozjs128_128.2.0.orig.tar.xz 64e3ee201dfa2a64548d3dd561ade862f2d65344 66748 mozjs128_128.2.0-1.debian.tar.xz 53fcd90c461425cdfc48534e420d0f9380b0b0d1 7940 mozjs128_128.2.0-1_source.buildinfo Checksums-Sha256: 176d9ec75d5601d2bdda80507c3974fea2e4373d13fcbad59be09b01c37d5945 2387 mozjs128_128.2.0-1.dsc 85fb7ddd93365c08d7547320a3114a19dab38b3045df198aee44a353d9233213 157072564 mozjs128_128.2.0.orig.tar.xz e02a5310221a0b33ea2c53bbb076c4da9f9bf88b52a0b3f1613f04ca47c903fc 66748 mozjs128_128.2.0-1.debian.tar.xz 3f3f82d9042b1f290bbe9ee3f70cfc3b9397ba6a72ddeba2f80c25f9280f036b 7940 mozjs128_128.2.0-1_source.buildinfo Files: f80e670bd02a29772cdc8b0b1414e271 2387 libs optional mozjs128_128.2.0-1.dsc 100842afe755cdda3dd3546323a0b897 157072564 libs optional mozjs128_128.2.0.orig.tar.xz 783a239b858838ece06fbd5e4d7b40fc 66748 libs optional mozjs128_128.2.0-1.debian.tar.xz 707c48af5d348468e6035e39dff63784 7940 libs optional mozjs128_128.2.0-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEETQvhLw5HdtiqzpaW5mx3Wuv+bH0FAmbYa/sACgkQ5mx3Wuv+ bH0K5A/9HPMWajmXUL29O1xGHf36QI7v0KzrwyskmVJECsGL5ZTV1iLmhq+yXnAw h93foX089WVNQ9O4XTPlV5ss/i4UJQnWFoTbwv29CydaDunkrHN094vZHX9ywn0o KaOwCOoYLCIMAtM4qZKuXjOARsTeB1gPpnfqCNOU1+51+nL8h04MzZwO4mlRuhj6 Z6ruyxImwywQbbua6C4vI2OxLaLnNTwrbCeHK3zGfo0dCa72K16FzDioF9S+6UGC yJIfwP685capTwekyzF2sNkNtcIIsMLB4yxoiS0DG0wtT3CVDWfgI+0I0cZHUz9g z5uDPb//ToErygmehLtNQ8YpHuyUmWGSlNAsTJIk4sDJqjV7mXV3wJdlljEATHgs j6xx2zkUXaHC2bwtpmv/n9Douw/eDOGWCbiSgduaIgyauyCfqUo36X5OtykWlidN E4kWL4uvJuLbxDXeV6gtc6Vsi+a3hJrZ+ilR6+g8yNcemltFT9KgGY7xHmlkEuSz wzvjAiqc2prtKv+jlIB+vTwt6o8mLFCeVHXbVlIcGdpqxLSbpJjjcDkTD8v+MoM6 UcTak83sA3kF38C052LWHQ6swmbDJmwR0XNyrwAXTtfjX+7NUUmKobsnDwxQkCFi PDbjF9rJlL725jD0t+AvK85H/V9IqqgwEah/WGb/hdrgIVH11O0= =Reiq -----END PGP SIGNATURE-----