-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 31 Mar 2025 12:49:25 -0400 Source: mozjs128 Built-For-Profiles: noudeb Architecture: source Version: 128.9.0-1 Distribution: unstable Urgency: high Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org> Changed-By: Jeremy Bícha <jbicha@ubuntu.com> Launchpad-Bugs-Fixed: 2105631 Changes: mozjs128 (128.9.0-1) unstable; urgency=high . * New upstream release (LP: #2105631) - CVE-2025-3028 Use-after-free triggered by XSLTProcessor - CVE-2025-3029 URL bar spoofing via non-BMP Unicode characters - CVE-2025-3030 Memory safety bugs Checksums-Sha1: 186422a9992612f0b7082e7c324b88ff37cb1e29 2409 mozjs128_128.9.0-1.dsc d3148a5364c50a023a48ec9de24e0a3ff2a2f9a0 157072488 mozjs128_128.9.0.orig.tar.xz 5cd1cc4f4a95d07a51c2ed50aa89bddf9ba39cb1 67676 mozjs128_128.9.0-1.debian.tar.xz fd5b9c94757b4643f0de200e50e46ff5d42fae47 8763 mozjs128_128.9.0-1_source.buildinfo Checksums-Sha256: 60c37111969d8035f5fa5d68ba7cab910847f94de85553522672b80dde0d45c7 2409 mozjs128_128.9.0-1.dsc ec7193af3edb0ad6706ac1e88fe4228de1e438b15a46d7b023934d9960ce8c2c 157072488 mozjs128_128.9.0.orig.tar.xz a1b054dfaddbbef1f23870d52fd7cf0dcdadef423f7ccf01e8f36ac9dd6c004e 67676 mozjs128_128.9.0-1.debian.tar.xz f312add09b7c60188842b473900a7d9cc13ef3c37bd83f08bb16ce52a52ebf93 8763 mozjs128_128.9.0-1_source.buildinfo Files: b9f41411daefa46b3e40587921d7b7da 2409 libs optional mozjs128_128.9.0-1.dsc 05355fccbede856fde34a18aee674f4e 157072488 libs optional mozjs128_128.9.0.orig.tar.xz 86c7c5a295c9f74e4ba5f61fbd48f1bb 67676 libs optional mozjs128_128.9.0-1.debian.tar.xz 53f0ecbc9de9fdfed7066cd17e526325 8763 libs optional mozjs128_128.9.0-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEETQvhLw5HdtiqzpaW5mx3Wuv+bH0FAmftMmoACgkQ5mx3Wuv+ bH2RfQ/+PZ5+pceh3bCcRUpVAb6XHlsQZHZs1Cyt+hcXP55sUqtfB5U1+30khdT6 PnSdXSIFrViz56zc2IZclXjGodgxQ9EFUkzBRVAqXeJdO1c6dyALbA6myH8hJh/D 3xxDfBPk5LvckCuvUBZ3hcy3EPDB9kTJaYG+2UNlMiyZHIRljG7mgic10M0ARykl dL4Tv8gkaWf6Gl3OxB2xFAni5h+a75A+dr6b9lcxeQOV6NdEEcp6usfOLiL0v8EQ EoGAtcWt+nlXAyoLPB+Fm5y0xmVohOzZ8VSk7w0QC4Nvn7nSBCcxHRVkgMRrpqD4 LC0T1QPSqqI/c96cClMG27PVSgV/APr6AIPF09wLPbNmcYL0+SdUD7dCDiocLG7x O2uPaN1h/aaZzZIxoWGjR14473Z7OaIpLrvOCrmD/MkEEYJUexA7iObSkVsaIwun m6wAYlswmqV2+C6dWJCqZYeQ6JjuRwW22QSachCfkfgfDSfTOKcsSoYU/kcWaSy8 1AbTceCEnvowVfqD6XAWORtr/+FcpxXw6HEweJWjurzV47/H3b40DaXd63CgJq3P BLI3gFR+Q4H2OLdmd/KEcMwQHNXRJlGs8AzS3Xp6Qbbu8sRnKwHKFQHNl7s474Uc PrISWGu+TTJhjZkjtze53LfXPbYKo3FF2Y1Rp3MzMNwEvzjEArk= =1hFQ -----END PGP SIGNATURE-----