-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 31 Jul 2013 05:43:23 +0000 Source: chromium-browser Binary: chromium-browser chromium-browser-dbg chromium-browser-l10n chromium-browser-inspector chromium chromium-dbg chromium-l10n chromium-inspector Architecture: source all amd64 Version: 28.0.1500.95-1~deb7u1 Distribution: stable-security Urgency: high Maintainer: Debian Chromium Maintainers <pkg-chromium-maint@lists.alioth.debian.org> Changed-By: Michael Gilbert <mgilbert@debian.org> Description: chromium - Google's open source chromium web browser chromium-browser - Chromium browser - transitional dummy package chromium-browser-dbg - chromium-browser debug symbols transitional dummy package chromium-browser-inspector - page inspector for the chromium-browser - transitional dummy pack chromium-browser-l10n - chromium-browser language packages - transitional dummy package chromium-dbg - Debugging symbols for the chromium web browser chromium-inspector - page inspector for the chromium browser chromium-l10n - chromium-browser language packages Changes: chromium-browser (28.0.1500.95-1~deb7u1) stable-security; urgency=high . * New upstream stable release: - Medium CVE-2013-2881: Origin bypass in frame handling. Credit to Karthik Bhargavan. - High CVE-2013-2882: Type confusion in V8. Credit to Cloudfuzzer. - High CVE-2013-2883: Use-after-free in MutationObserver. Credit to Cloudfuzzer. - High CVE-2013-2884: Use-after-free in DOM. Credit to Ivan Fratric of Google Security Team. - High CVE-2013-2885: Use-after-free in input handling. Credit to Ivan Fratric of Google Security Team. - High CVE-2013-2886: Various fixes from internal audits, fuzzing and other initiatives. Checksums-Sha1: 565743edfa60616fef132da47ed0311f40a6ce5d 4371 chromium-browser_28.0.1500.95-1~deb7u1.dsc 89984edc35d7a44997851a5e75d860af3d1b33e1 1192468688 chromium-browser_28.0.1500.95.orig.tar.xz 7a10226c32390074d4bf1ebe20d465dff2b97f79 257509 chromium-browser_28.0.1500.95-1~deb7u1.debian.tar.gz 5f3a17c5009dbb7b46be940b943aa1a7b821e688 161278 chromium-browser_28.0.1500.95-1~deb7u1_all.deb 01a124f53dfff398cdb7c16e71cdc1776ca92144 160630 chromium-browser-dbg_28.0.1500.95-1~deb7u1_all.deb 7d392a46f4accd5ffb886cac5797ca750c81866e 160810 chromium-browser-l10n_28.0.1500.95-1~deb7u1_all.deb f98a317596acf9d205ac94a6f9c813b7485afa82 160670 chromium-browser-inspector_28.0.1500.95-1~deb7u1_all.deb 539e57323522a1840b8786ddd646cd9610570787 2685988 chromium-l10n_28.0.1500.95-1~deb7u1_all.deb 490e63f91f47c48a2938d90e335dd33fd13d42bc 742512 chromium-inspector_28.0.1500.95-1~deb7u1_all.deb f388cac3aa60e5ef38fec6bd2dc06405657da2dd 43654402 chromium_28.0.1500.95-1~deb7u1_amd64.deb a62f8dff8d7e706ce6bf521665f6d08530cf85e8 431343112 chromium-dbg_28.0.1500.95-1~deb7u1_amd64.deb Checksums-Sha256: 3e23e8bf8c8515a52bf21ada68fef273000242ed15ef74dd48f0b3138c5030fa 4371 chromium-browser_28.0.1500.95-1~deb7u1.dsc fdd883828731b4c4faad5b6ed879abe41a14805689e379c94591fb18b85a431f 1192468688 chromium-browser_28.0.1500.95.orig.tar.xz 4fff1ce58630968b3e3412b9ac897fd24d3217b2019a1d6cb77bc76f13081db1 257509 chromium-browser_28.0.1500.95-1~deb7u1.debian.tar.gz 6492cc9c8d5a86457fdaa0da972f6b931353ea7d265807ac88b9fee9fd6fdf5b 161278 chromium-browser_28.0.1500.95-1~deb7u1_all.deb b774da43877ed364442ac1197fce48cdea17ac2e72b994a12a6a004fff9c49eb 160630 chromium-browser-dbg_28.0.1500.95-1~deb7u1_all.deb a096491ef85a62f518893448e338d8b8fdb6dfbe92666b559ced20072707744b 160810 chromium-browser-l10n_28.0.1500.95-1~deb7u1_all.deb c9412bae44978f9c563cd31181342af6b72204c7d384262d01956e2024db5a92 160670 chromium-browser-inspector_28.0.1500.95-1~deb7u1_all.deb 43b1acb3acf2ad843a545f7d2e54f5990a062c1262307bcf1c96b34126f9baa0 2685988 chromium-l10n_28.0.1500.95-1~deb7u1_all.deb b5129ba4dc3bd82f4d7abd3bb48dd0f92b6ebf4f4c26f62979f4d63cddf1bc2a 742512 chromium-inspector_28.0.1500.95-1~deb7u1_all.deb 8482ada0839c1be9d0247bde06c6a7381dfe1a0ae87f52a1c27a25194045de69 43654402 chromium_28.0.1500.95-1~deb7u1_amd64.deb 11f283500f74a12ba5dcf5f1eed9856a267ea12ff9b409601aa58ec68ce14291 431343112 chromium-dbg_28.0.1500.95-1~deb7u1_amd64.deb Files: 6daa3d4ac6cb4cb98971f7cd04a0005e 4371 web optional chromium-browser_28.0.1500.95-1~deb7u1.dsc 535427e7812dc5af4f28d5a6195923db 1192468688 web optional chromium-browser_28.0.1500.95.orig.tar.xz 159788148678d0c3d34c130b2565e1e6 257509 web optional chromium-browser_28.0.1500.95-1~deb7u1.debian.tar.gz 35f72e768cdcb3427aa050b464d696d5 161278 oldlibs optional chromium-browser_28.0.1500.95-1~deb7u1_all.deb 94179166b18831a98e5b9ebc72a5f903 160630 oldlibs extra chromium-browser-dbg_28.0.1500.95-1~deb7u1_all.deb d7760b067ce170261c4a9cfe15955511 160810 oldlibs optional chromium-browser-l10n_28.0.1500.95-1~deb7u1_all.deb c7ca6aee97e65e31e7e5a670e133f6da 160670 oldlibs optional chromium-browser-inspector_28.0.1500.95-1~deb7u1_all.deb 22dc5a012588e6afee96007a30649c46 2685988 web optional chromium-l10n_28.0.1500.95-1~deb7u1_all.deb 71698c5652a01fa53ec202336bc33843 742512 web optional chromium-inspector_28.0.1500.95-1~deb7u1_all.deb 025599912409cdecb1f6cba2e32160dd 43654402 web optional chromium_28.0.1500.95-1~deb7u1_amd64.deb 23380f79289f55925d57a3ea9fecd5ce 431343112 debug extra chromium-dbg_28.0.1500.95-1~deb7u1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (GNU/Linux) iQQcBAEBCgAGBQJR+V7ZAAoJELjWss0C1vRz+DggAI9lRwvsp2O9gOJRKKKgMiM5 O5kG/nxNN18UmaPfRbDw/yyqrlnOP4CzFLJr3yR2kRtskktGvV8Q+yxifre1QZME Pzgw56YQOhxDopU/7NoacLbuiKsp/6qS+ccUP+sVOQjhz1qEeSkehhlOJnqpCWgX atklSzs+lOPak2mhFGgIDRQ1nOLFtVpWNU6u8d7r8TOqBxjEp2GwaW2pEyUEgQhw NGTiQk21TroV3WVjcBv7Kk5qiORQUR48hiWIu7Bfq9EofS6cVNUgf7T2T6+dLRa1 cvbqdCCxzKV3jZOMAna9puRVGIqbWY6ZTBpxclq6PmKbwTNt2BUKp4prOO78FZc4 33nxXwuNCazhD+a4bNGthkULC4AfVp2XMbvpnKgNVKyM2/mqGBxt20jzl4c8z367 HXnP8q7Qw+OGYxLQA33sxs0exe+k27B+cvalcLuauGOmAEmlIsQZSVGoSWyt6m3W PsDWt2QX89F0T6n3NKPQ8TmpNw9sqxFV3p1bS6PYexYaa29StuisC0hYPny+2s55 0yiEvos+oabwSv+LwYYbm6orSF0fQRRBzSUVqJybJS61bJw2gN3UBLp+5Gp7LgeE fGZqFjks7VH8/1mZ9f69hj5DJ4j7P51HeAofl47yHRU28LYbKhgEjjfAkC8z0Dk2 U1GevKXRR/Nvgc3LxsxZTvEjTiyu+j76IGHmZJMnbS0eqSBOUavXdIr96S3OUlcz sMhWwo5kkv2AYMQNoPVfIHJ+OMTY7G923M0XWsYZ+cFvlOM8UMsPHEARimgz0Zx+ JsZtRtpmwronGqGaHPnEtVT4JxoQLdhm+7rzcmjhHN8tA9s/L5smP+uNGnVar+7p JzxBEjEo8cecVOWrMbF6wK8m4kmlYf+aELCniKpDJLABIH7GcSW9fXRd0XwYhzZJ iLpEgCKs+dTSvy8yXnz1QWFHLQP5DozeO8B4rg0K8916Zl1b6keFi+b4jfzo1iKp tLqpDHhqzVIni02y7/BTvoX0FGK5GJgUhh0xl9aJbMt9wms+0CyYHg5gvhRqwtZk 1D7Eu3uZaaujJEbzvXmt6VVmUF8ixhuBuc92llm/QKQ3rl9KAd1Gof9cTmssHrYJ SqKZw3NBePoo0R2O9HibAyTd7Aj6ylK2JkQd6TY9B9M0muOlX4FEH2/AfKp0DRr3 XIZ7ce1l5syMO8wBHcdbcdEVRgWjA+SaMEiQ7f4jTKcPHZNMzj+kdAQNgJdkGCAE H3lgeH9iC9+gzbryZoiONX/KIjkiEz1Us9M5aHcfyfw/J2zO17BD0QU9H/gUN/UJ EjMiifyaDBdbF7udsF627+wyTQRlWQTiHqkXkxG+4Zrjfeo9ofk7rqWzBueUlQ4= =OHxX -----END PGP SIGNATURE-----