-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 22 May 2013 03:03:49 +0000 Source: chromium-browser Binary: chromium-browser chromium-browser-dbg chromium-browser-l10n chromium-browser-inspector chromium chromium-dbg chromium-l10n chromium-inspector Architecture: source all amd64 Version: 27.0.1453.93-1~deb7u1 Distribution: stable-security Urgency: high Maintainer: Debian Chromium Maintainers <pkg-chromium-maint@lists.alioth.debian.org> Changed-By: Michael Gilbert <mgilbert@debian.org> Description: chromium - Google's open source chromium web browser chromium-browser - Chromium browser - transitional dummy package chromium-browser-dbg - chromium-browser debug symbols transitional dummy package chromium-browser-inspector - page inspector for the chromium-browser - transitional dummy pack chromium-browser-l10n - chromium-browser language packages - transitional dummy package chromium-dbg - Debugging symbols for the chromium web browser chromium-inspector - page inspector for the chromium browser chromium-l10n - chromium-browser language packages Changes: chromium-browser (27.0.1453.93-1~deb7u1) stable-security; urgency=high . * New stable release: - High CVE-2013-2837: Use-after-free in SVG. Credit to Sławomir Błażek. - Medium CVE-2013-2838: Out-of-bounds read in v8. Credit to Christian Holler. - High CVE-2013-2839: Bad cast in clipboard handling. Credit to Jon of MWR InfoSecurity. - High CVE-2013-2840: Use-after-free in media loader. Credit to Nils of MWR InfoSecurity. - High CVE-2013-2841: Use-after-free in Pepper resource handling. Credit to Chamal de Silva. - High CVE-2013-2842: Use-after-free in widget handling. Credit to Cyril Cattiaux. - High CVE-2013-2843: Use-after-free in speech handling. Credit to Khalil Zhani. - High CVE-2013-2844: Use-after-free in style resolution. Credit to Sachin Shinde (@cons0ul). - High CVE-2013-2845: Memory safety issues in Web Audio. Credit to Atte Kettunen of OUSPG. - High CVE-2013-2846: Use-after-free in media loader. Credit to Chamal de Silva. - High CVE-2013-2847: Use-after-free race condition with workers. Credit to Collin Payne. - Medium CVE-2013-2848: Possible data extraction with XSS Auditor. Credit to Egor Homakov. - Low CVE-2013-2849: Possible XSS with drag+drop or copy+paste. Credit to Mario Heiderich. Checksums-Sha1: c5f689dd5d2845eb65b7853bb74925f8efa85059 4368 chromium-browser_27.0.1453.93-1~deb7u1.dsc 98d3c1c3d171d11164577266223bb2b01f5c8d9d 687283656 chromium-browser_27.0.1453.93.orig.tar.xz ecc4c197e64dfd39188338dd93f94dce2485d137 257567 chromium-browser_27.0.1453.93-1~deb7u1.debian.tar.gz 31baf277dffd8b925ab9275ea24d3244030964f2 160474 chromium-browser_27.0.1453.93-1~deb7u1_all.deb ef4835fa3928660b51983354ce3554781bb4afd2 159824 chromium-browser-dbg_27.0.1453.93-1~deb7u1_all.deb 2e1055396f01ab0f1d7881f428245c3f37d7edfd 159940 chromium-browser-l10n_27.0.1453.93-1~deb7u1_all.deb 3d807f511819d4ca43304dec5d36b886e858b51c 159880 chromium-browser-inspector_27.0.1453.93-1~deb7u1_all.deb febee2d13b73797b734dffcfdf6fbf945b723b0d 2652998 chromium-l10n_27.0.1453.93-1~deb7u1_all.deb 7ff37047b9e2084509c9f488bc3c5599fafd20cf 948712 chromium-inspector_27.0.1453.93-1~deb7u1_all.deb 17962e4734e8a08ad4b265312da71678a1b35c6d 41232208 chromium_27.0.1453.93-1~deb7u1_amd64.deb 5750f71b094ffa4dd0715bd0bf4e3df0b969c4a4 432873792 chromium-dbg_27.0.1453.93-1~deb7u1_amd64.deb Checksums-Sha256: f9ca32450abac43a7ab42f4099766d383998b216929e9490aefbd9326c087aee 4368 chromium-browser_27.0.1453.93-1~deb7u1.dsc c135ffbca47ceb6a81e3ff6a2fa42f73b2dfc7235a9896f7791cf8f5adf44789 687283656 chromium-browser_27.0.1453.93.orig.tar.xz 18aae46a8b83ca47ed9b304dd8d31be00246c28dce81e542dae18e5849be401f 257567 chromium-browser_27.0.1453.93-1~deb7u1.debian.tar.gz d049730281e6dc024cca1a14d2ec6314c3a364bf170e4fcb6a8836b5b87a984d 160474 chromium-browser_27.0.1453.93-1~deb7u1_all.deb d1317deeb3976a8807a270d4103c4f5b0ba666d88accc5ed695aae94aad55966 159824 chromium-browser-dbg_27.0.1453.93-1~deb7u1_all.deb 7e58464486fee60647a9c46003e78d1eb2330a8648412ca9a954c64ffdb0a527 159940 chromium-browser-l10n_27.0.1453.93-1~deb7u1_all.deb cda1f7ff896e9dd91943bd0cb620278fca60826571b5bc64888896438aae8485 159880 chromium-browser-inspector_27.0.1453.93-1~deb7u1_all.deb fc30952e37dff5bd1695d8c71b3d9a8d30d23016272584e202ffe0bc58599234 2652998 chromium-l10n_27.0.1453.93-1~deb7u1_all.deb 342b3722f8647b5a5f4a3360dca75c497ab7e44ec8692040a51b9096802d67a7 948712 chromium-inspector_27.0.1453.93-1~deb7u1_all.deb 8cd9ee4e8b22ef29c4b09f0890f0cda69fb1d42a913ad95a981d4434a9b0b0e4 41232208 chromium_27.0.1453.93-1~deb7u1_amd64.deb 69f3c00a63807bcc4ce3d147bdd7a3778650dadaaf7a0fafca431dffe06c19c6 432873792 chromium-dbg_27.0.1453.93-1~deb7u1_amd64.deb Files: f9adb0ec83f0ee27f445f43c487bab02 4368 web optional chromium-browser_27.0.1453.93-1~deb7u1.dsc 97d6062b957c38344c8a5a298268219d 687283656 web optional chromium-browser_27.0.1453.93.orig.tar.xz 20210c6ed2668aff328eec368a873960 257567 web optional chromium-browser_27.0.1453.93-1~deb7u1.debian.tar.gz fc431de90050ecd3dcc28ff43ede3208 160474 oldlibs optional chromium-browser_27.0.1453.93-1~deb7u1_all.deb eccb877c8a706fd7f43b8c660a481afd 159824 oldlibs extra chromium-browser-dbg_27.0.1453.93-1~deb7u1_all.deb ed10bbe653335c750ce659a3aebd0151 159940 oldlibs optional chromium-browser-l10n_27.0.1453.93-1~deb7u1_all.deb d6b9a18a9cbe7b12f704e2635ef15b4d 159880 oldlibs optional chromium-browser-inspector_27.0.1453.93-1~deb7u1_all.deb 2cb71e4358899737e4ecb9bb65200e2f 2652998 web optional chromium-l10n_27.0.1453.93-1~deb7u1_all.deb 286093d22cde0a5fa8245f82b8a0f0fb 948712 web optional chromium-inspector_27.0.1453.93-1~deb7u1_all.deb 52f5b4ff70acb78d09804d5857b85118 41232208 web optional chromium_27.0.1453.93-1~deb7u1_amd64.deb 2479b238a91b6f8e94f0af2f1cd82142 432873792 debug extra chromium-dbg_27.0.1453.93-1~deb7u1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQQcBAEBCAAGBQJRoSmuAAoJELjWss0C1vRzJXogAIMV/cURSFo3O5SrZgqh7KNW cOcsY8RWToblCzpxS9NQN3o45fVXGUDKN74aaweA/UnSDx9yvxOwb7dO8+byoNrp kQ3yOc6wCYAGCd2COOPmRaWNuNnmd3flDftErom+t+bt1OCtJMtuVnhAFqWV5b8k vaSx8ubpM1pggTE2xuAk6gcaAzqFDbOD7DfV8i8bMjd0hQnllVNVme4htbWichKl 6GT/5gMvakHoFyeAG7B6c7w6wy97/cGfh/BsFXZgshLDWAic02oGcDR48vXKKY4d 0F53tZdjtl2jsXd6IfZ4zxAlZOhrEXCxZ+rNOALfhSPqiHk5r16K71jy5VoJCcGl Sw3srmYK8veiDFi1K5vIknouk7NYp9WABGuFaQ6/cjeixlA9bGPQPL6V7mLzVDML +X6SdhssX6fiVtGUPXxXDiDNEIgZRvqOSSm+oCBn0xbUIkyeaMqHrq9LdzW8H//W CMx5BBrvqw7kInOFO2wXKf4YxY3ilLbyuDg8ja3s4ubzw01W8KgqDvB7iIsH/P94 CLGnUQ5t0aS4T7F7JXySEH2h9qH5KK0oaYVdSZ9XhxWlSns+ci3OJkc0lYZ3k/JU lt2pwKuDFKepyeqFtOoM/8MpWrkkCHzRekaIKq1TVuo8UdhxIMe3KMcjBsQK3YE8 A09e7ARsaIp2SmN1ZxyUfHGo4XmOXznw7WSKJDyNtUfjTnEYHDoutieAbitfimMu eiTWwXPMLz9ZDqUU/GpA+WLxfz/upEGO5VowcABKrzryudRUgzxzQlJXS9+IhaKA shxYbn42AaxWAjql4f4TvFSgDZfUKXBPWkuANYBqwFzmkCQxhF7V1vr8JHb4qwA1 5cb4+VayUy2iYTGnhxDJVI7FiZVB8zxfNMfO7gtWGWGpnZgeFBtZHFQI5Qbhsxz+ juG2FNix96hdzTrma1a9f2JsYlvP8JRRXCfduno5kE3TGwXeCdg3vQn4K2lLOEEY q1LpAHRnJEQikRL/H4FOAuoGW8NaXGCC+ZlsCb6SD1tjW9r2Rtp7WfE6RVdnkPoa s8bJLeoyYky1dAP1DBjBzHNm4tFiqV08qmC/jmeomcX5cZE9pv+u/O3uLvzKAxz1 PSxtKSDgppU+2CzUaWqG3EvvHKC2zMciN46+HeRpV6SfSWGfygvbT8NtGoQn480w oJ/+NRkRseq/Hntq1uQUYGz1V0fr5TeaSgp0Xd1jHlWngSrBIko297Nh2h3ZoSsi AJ8OGRYQeVsoCo/UEP8ACnxGHWF2Q9lbbens1dM/gk6+uKr9Gj5sssAkisVIUV2q 1PDskzhchNEsBrIXbDdg1s7nxcUl4sv/ALrJ6GYw7etHGoXhBjWUV8NbdRjBpYE= =1Mdy -----END PGP SIGNATURE-----