-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 22 May 2013 03:03:49 +0000 Source: chromium-browser Binary: chromium-browser chromium-browser-dbg chromium-browser-l10n chromium-browser-inspector chromium chromium-dbg chromium-l10n chromium-inspector Architecture: source all amd64 Version: 27.0.1453.93-1 Distribution: unstable Urgency: low Maintainer: Debian Chromium Maintainers <pkg-chromium-maint@lists.alioth.debian.org> Changed-By: Michael Gilbert <mgilbert@debian.org> Description: chromium - Google's open source chromium web browser chromium-browser - Chromium browser - transitional dummy package chromium-browser-dbg - chromium-browser debug symbols transitional dummy package chromium-browser-inspector - page inspector for the chromium-browser - transitional dummy pack chromium-browser-l10n - chromium-browser language packages - transitional dummy package chromium-dbg - Debugging symbols for the chromium web browser chromium-inspector - page inspector for the chromium browser chromium-l10n - chromium-browser language packages Changes: chromium-browser (27.0.1453.93-1) unstable; urgency=low . * New stable release: - High CVE-2013-2837: Use-after-free in SVG. Credit to Sławomir Błażek. - Medium CVE-2013-2838: Out-of-bounds read in v8. Credit to Christian Holler. - High CVE-2013-2839: Bad cast in clipboard handling. Credit to Jon of MWR InfoSecurity. - High CVE-2013-2840: Use-after-free in media loader. Credit to Nils of MWR InfoSecurity. - High CVE-2013-2841: Use-after-free in Pepper resource handling. Credit to Chamal de Silva. - High CVE-2013-2842: Use-after-free in widget handling. Credit to Cyril Cattiaux. - High CVE-2013-2843: Use-after-free in speech handling. Credit to Khalil Zhani. - High CVE-2013-2844: Use-after-free in style resolution. Credit to Sachin Shinde (@cons0ul). - High CVE-2013-2845: Memory safety issues in Web Audio. Credit to Atte Kettunen of OUSPG. - High CVE-2013-2846: Use-after-free in media loader. Credit to Chamal de Silva. - High CVE-2013-2847: Use-after-free race condition with workers. Credit to Collin Payne. - Medium CVE-2013-2848: Possible data extraction with XSS Auditor. Credit to Egor Homakov. - Low CVE-2013-2849: Possible XSS with drag+drop or copy+paste. Credit to Mario Heiderich. Checksums-Sha1: dbff185bb50af3c93ee9d6eaba842776ddde093b 4340 chromium-browser_27.0.1453.93-1.dsc 98d3c1c3d171d11164577266223bb2b01f5c8d9d 687283656 chromium-browser_27.0.1453.93.orig.tar.xz 8eb654b4e955afb6318b2e85a05ebcf520454db1 257787 chromium-browser_27.0.1453.93-1.debian.tar.gz 12f5b3d0767544476bd784ebd0334ce4c1bdc08e 160504 chromium-browser_27.0.1453.93-1_all.deb 8093c94f29244e117b235d26b3134ff0a4d41a24 159778 chromium-browser-dbg_27.0.1453.93-1_all.deb 37f9375451065a681b66d6e921445f77f122425c 159970 chromium-browser-l10n_27.0.1453.93-1_all.deb 316a7e6ff81dd66898696df0a62c68226b4a3db6 159834 chromium-browser-inspector_27.0.1453.93-1_all.deb 67ebfbceab26abdd5a9b820dd8485b89b5405187 2635214 chromium-l10n_27.0.1453.93-1_all.deb fdde1b4745b692fda02e8f431ec9e1d932573ee2 948478 chromium-inspector_27.0.1453.93-1_all.deb 44443f4c194162f3308116a815fe6821c41e8aca 41143054 chromium_27.0.1453.93-1_amd64.deb a6d593dbbe7d564f27f851711b8895f6fc4654d8 432716524 chromium-dbg_27.0.1453.93-1_amd64.deb Checksums-Sha256: 06c9cee44e44364314b37a7258888bd628a8dc9176be76ac65bcbc0ef0585e7e 4340 chromium-browser_27.0.1453.93-1.dsc c135ffbca47ceb6a81e3ff6a2fa42f73b2dfc7235a9896f7791cf8f5adf44789 687283656 chromium-browser_27.0.1453.93.orig.tar.xz 8a86eb6d23307982d17bc5e16a00b781b48f81fbd0be1ec78576555f7626013e 257787 chromium-browser_27.0.1453.93-1.debian.tar.gz 184355226e1c8e31da79e9d822a393481fcd09ccb1f71c8cb20989e6d30d0183 160504 chromium-browser_27.0.1453.93-1_all.deb 0b921903171e6e30cc33ec6cec3521326a8a264d9d1962001d822082759d1dbd 159778 chromium-browser-dbg_27.0.1453.93-1_all.deb 0d1c450011a95c16b75b5948ff34e3ba8576f2cd4a5b8440e87a3c6e2503ce87 159970 chromium-browser-l10n_27.0.1453.93-1_all.deb f23bd1ec7819efeee9fa4747f8127e18ab8629774925a4dccb2be924a38333b0 159834 chromium-browser-inspector_27.0.1453.93-1_all.deb 160ee1e04040f68766a51115ee67b812743d4a2cf282e2caf15a76bbd1bfbfae 2635214 chromium-l10n_27.0.1453.93-1_all.deb 44fd950fcdaeb958f124f214a89df363ad56722e791b282e95017f95510f6bea 948478 chromium-inspector_27.0.1453.93-1_all.deb 3cb0c3360008ed743bea35caf5c13fca73eeb1bb3fb0882c1b7c626b15631eca 41143054 chromium_27.0.1453.93-1_amd64.deb 1184f76bf8b4519c6e93db2e9a2c7255799c678d8251e0e415309380bf4abaae 432716524 chromium-dbg_27.0.1453.93-1_amd64.deb Files: af107df2383295aff85efd4768f50267 4340 web optional chromium-browser_27.0.1453.93-1.dsc 97d6062b957c38344c8a5a298268219d 687283656 web optional chromium-browser_27.0.1453.93.orig.tar.xz ddbda9268469f48af29241ee1be1d9f6 257787 web optional chromium-browser_27.0.1453.93-1.debian.tar.gz 2cc72bac509fd8fa543c110cc8442f85 160504 oldlibs optional chromium-browser_27.0.1453.93-1_all.deb efb6030af2041e0441ba1714d0841395 159778 oldlibs extra chromium-browser-dbg_27.0.1453.93-1_all.deb e8aeecb6ba4935c60ef2295446ae9be2 159970 oldlibs optional chromium-browser-l10n_27.0.1453.93-1_all.deb 70e3a4572aee6ed9bc75c322dc9c60d9 159834 oldlibs optional chromium-browser-inspector_27.0.1453.93-1_all.deb 1b52a3abec1d461302e403a266bd336f 2635214 web optional chromium-l10n_27.0.1453.93-1_all.deb 742220ae673c798d31dc479931274f88 948478 web optional chromium-inspector_27.0.1453.93-1_all.deb 69613e765ac56df885afb67bb7989731 41143054 web optional chromium_27.0.1453.93-1_amd64.deb 2d6f74cc70e8c2b10023e2723b0ddd62 432716524 debug extra chromium-dbg_27.0.1453.93-1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQQcBAEBCAAGBQJRnT5AAAoJELjWss0C1vRz81sf/jgkA8d0f9HqrC6IPFIXoepn ax+pT1P8XP5X120ANLSypI1bMIzzzQfFuiJDbVWv3J+Euhb8tOj6360GdFuwf5f9 UzOJGSNcLbJ3ILNoWj2hEnR/B2dwpmq4ofocx4vUDfj7EuEyG/JcTp2ge940CXVz ccJhnA6+RtbR6XjHoarBs4KouSqNUpPSaX73aGLs0ROhv06Kb5ZTi//HRmyRgX1z KGl4hFZLG2qCKxMd45kfN22JWf7u1QQWul29nW1by1RZ/BfbfczNV76/R2kbjdOc VycNmLa9m1myRY+DrEKSztendS6MKtKf9ZZqe0HOG1C/4m03KCCvhZHs7UHnuixr QOVz27fhw6Itz137vKhp86A3cPLDKIXyj2/69vcMIdT6JbnFbpfjccBzx2zLbplD qGLKzis7XQw1sdDp9kxQrhyTj1caSGAJ8oRoJdluXyIf7jcQduAEZFCod5ylxBbI mifZ+6BKOtuATZgHHIj6M+RPVIc+FPCnn/OotCVJ//tx0HkelcCgy3MKSzCsrTrN bn7mW7l/RPNSwwY9wWs2D++7aVVjcFAXpvbrPsa9yJmXVPbVkNCPAmvkcUNf29RY giopwomcsZN/w9XGJ6AAe+RLewyEm/yNZQtIwj/dXSm0aUa4MvUse40ne1vuqwSF 5xE8QuGepCgnRaWVdQcw/uKq4KxCzQ2ADrpWdyw0qSKtVJg05mlBoSU0g7dHkxc5 ZWzcsLMAKzCoJ8kdYdQKxBFdhALTXOI+qclFx08VY3IJ9ovpJYsdxOjVt9WlC9CI GXJf+BdzAgvcTxD2AE5p3jSYBoQ6sIesBLEa9rXZql90HpAXtIktLsbqYThhBkaX El7J1LhyHiRHCQ/oVdGA/fWXalTu/C18SU12M5/Vfc7N/Z9OoEf5gfBuCfQce9IV 6pwZ4nFKpMXhdXrO7K25lvtWNw5mYszlj6DDwRg2aFMYu35G1DGVYCHiU5WlunXW bgm1DLGr0J3XzrxxHw7fNRagp0NGX2vjxB6muft23hEKkAEcrsPru9xbj2CVIKBn MXewlnKIhYlzyDPXQuAfEc+vnXNp/KnMPFZ5zng8sZwR5j9UdtRzi8B4ngcushMX yfzL0+0fqVMZ3JCYkKlnMQbWCyJc5sCDXa/e4+Xbqy/4DkGK15kHH1kWrJO2u5h3 jgBEuIGgzOkMs7z86EnilmQnzRdW1K6QvqGKenG6PjWM5mvanfphDRHSY7VSPgFL 28xs32iLxxTI2DMD4eQDB2Kwww9Gv7jcWEvi+sC1bGW9Mqmye6OGPpF3tzGECESR KzC5nsn8Dy+tJYknCsir4uMqRKzTcfoFYLSJLvRxBLfTAZzSa7XxxomUlT8s/ls= =Ck6/ -----END PGP SIGNATURE-----