-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 13 Nov 2013 07:44:55 +0000 Source: chromium-browser Binary: chromium chromium-dbg chromium-l10n chromium-inspector Architecture: source all amd64 Version: 31.0.1650.57-1 Distribution: unstable Urgency: medium Maintainer: Debian Chromium Maintainers <pkg-chromium-maint@lists.alioth.debian.org> Changed-By: Michael Gilbert <mgilbert@debian.org> Description: chromium - Google's open source chromium web browser chromium-dbg - Debugging symbols for the chromium web browser chromium-inspector - page inspector for the chromium browser chromium-l10n - chromium-browser language packages Closes: 589654 634101 725350 Changes: chromium-browser (31.0.1650.57-1) unstable; urgency=medium . * New upstream stable release: - Medium-Critical CVE-2013-2931: Various fixes from internal audits, fuzzing and other initiatives. - Medium CVE-2013-6621: Use after free related to speech input elements. Credit to Khalil Zhani. - High CVE-2013-6622: Use after free related to media elements. Credit to cloudfuzzer. - High CVE-2013-6623: Out of bounds read in SVG. Credit to miaubiz. - High CVE-2013-6624: Use after free related to “id” attribute strings. Credit to Jon Butler. - High CVE-2013-6625: Use after free in DOM ranges. Credit to cloudfuzzer. - Low CVE-2013-6626: Address bar spoofing related to interstitial warnings. Credit to Chamal de Silva. - High CVE-2013-6627: Out of bounds read in HTTP parsing. Credit to skylined. - Medium CVE-2013-6628: Issue with certificates not being checked during TLS renegotiation. Credit to Antoine Delignat-Lavaud and Karthikeyan Bhargavan from Prosecco of INRIA Paris. - Medium CVE-2013-6629: Read of uninitialized memory in libjpeg and libjpeg-turbo. Credit to Michal Zalewski of Google. - Medium CVE-2013-6630: Read of uninitialized memory in libjpeg-turbo. Credit to Michal Zalewski of Google. - High CVE-2013-6631: Use after free in libjingle. Credit to Patrik Höglund of the Chromium project. - Critical CVE-2013-6632: Multiple memory corruption issues. Credit to Pinkie Pie. * Disable promos by default (closes: #634101). * Set WANT_TESTS=0 if WANT_TESTS=1 fails (closes: #589654). * Maintain window ordering when new tabs are opened (closes: #725350). * Install chromium-inspector files to /usr/share instead of /usr/lib. * Don't remove third party libraries from the upstream tarball. * Remove non-default compression selections from debian/rules. * Build with breakpad crash reporting. * Fix some lintian warnings. Checksums-Sha1: cab1a275dde01f2caaf00bfc201419f75d8cd061 3890 chromium-browser_31.0.1650.57-1.dsc a537064d6b8bbfe23527ccf1ca5007e89abed649 646262684 chromium-browser_31.0.1650.57.orig.tar.xz d8c519daee838fb27d8827a80cd1037d83e39714 254592 chromium-browser_31.0.1650.57-1.debian.tar.gz a92d9b55da41a0c08a0625592a9fbd0b595ae565 2945614 chromium-l10n_31.0.1650.57-1_all.deb 7b176914458a4c1302c652a7242f031750885c0c 699902 chromium-inspector_31.0.1650.57-1_all.deb 121eb8968acbf13b85ede13fe1164eebeed03dcd 37026716 chromium_31.0.1650.57-1_amd64.deb af9b371e576551fc91921a924808367cb035983c 518686586 chromium-dbg_31.0.1650.57-1_amd64.deb Checksums-Sha256: 36851bd3a0268be8eee08ae4af3f89885e0718d782e9ff2084b9dd0e8503eeee 3890 chromium-browser_31.0.1650.57-1.dsc f7d2f1ade62457467670745ad8ddc46b2ff79f5550fe77b8b909b48217789a15 646262684 chromium-browser_31.0.1650.57.orig.tar.xz e9aa2b20bcb0f6f408998a0b779486708520738d7e89ffbe4153020551b5faf3 254592 chromium-browser_31.0.1650.57-1.debian.tar.gz 989941d2e99027e44e2f98b28883951c088a4096921dba1d950bd1277a3abb39 2945614 chromium-l10n_31.0.1650.57-1_all.deb 579fc1da4135aad60b255fb71d700ca4eb24b6556652ae6b05ff0e509693e19d 699902 chromium-inspector_31.0.1650.57-1_all.deb 9655ab2d22bc7d76fba3292e0d465a79c33a306039ad91231fd896b0388f8670 37026716 chromium_31.0.1650.57-1_amd64.deb 03b4dd4a17a3ffdd9fad01e2bdf76c713dc572d8e0d5e77720a805063d755b3d 518686586 chromium-dbg_31.0.1650.57-1_amd64.deb Files: 28ed035a37e9d62c84b293aca3443357 3890 web optional chromium-browser_31.0.1650.57-1.dsc 06a59b8024f3902b8b3524ef32fd8635 646262684 web optional chromium-browser_31.0.1650.57.orig.tar.xz 7f2b0ff474dcdadf6b8e76e418410443 254592 web optional chromium-browser_31.0.1650.57-1.debian.tar.gz 3337ffc287c65f4c4754c95c6f06e699 2945614 localization optional chromium-l10n_31.0.1650.57-1_all.deb 8e9e7d279a465f7a3e518d8dfe97632c 699902 web optional chromium-inspector_31.0.1650.57-1_all.deb 21df6129122b8b9e6621fcd7a1578a1e 37026716 web optional chromium_31.0.1650.57-1_amd64.deb 4bdaf46061575d3d9ac4c3ee1e5d13d8 518686586 debug extra chromium-dbg_31.0.1650.57-1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.15 (GNU/Linux) iQQcBAEBCgAGBQJSh/noAAoJELjWss0C1vRzHJcf/Rq6kMi0jS8EQv33cqgRifJ5 yJA1kUhKJMtH8qWypdYg+nN7Qt8SvAB8UPrhYrmMdfDV2n3vQxjVr8KKznmpqMla 6cWB5qyDr70Gu232F/9vQHNUAMYdzGZCm0r756D43BChjVal6k5wPgFNnWO4zxqg vpyo3vcXnyEaRnPyhlPh25CuTucDsVcnie/y4ezw4jlqDBRmSbEF6yJ72TOyH4G1 IDWthyfBvBKAQIMMrobwnFSEwFFQUoqngUYfBxozAjy37vEWJJjO6aUT4MwCwwxe /q7AzSenXTmawvJj5Kn00M/Gi7HDhsch4TxADyIKL8obfL1PtD8BbcS7dZNfugd/ +lx6AuaVKJnhV11sx99D79V8eKEuXx/GEwhvHayv9FBcAg13O5UESC2zAcia53fd UZ9hEyG9kGbf8mCtYO8XDMhc/4j6eeUNjR//BWoI2OOJS/0R/86u9KBUUJnKHCig dJcfp84fvV3GZrNerY1M7LL0NdYfoOFVFPlOu+0GrdukJDw2C6wNaFi5ofJ5NVy+ HjvnKLqmLGV0teIEJcRSrLy3NvZRvAVEmWd4Yg+NDI3XLkeJkAsCE1AcJKQaSlRu ncnHq1f/fI3hGh6sPhtI1z59h9kGv+IAC9mcWa/O6a9qmov1NyewSKnglrLuwRjU LbaXzcHW+Szuh6Byu57yIUmgFP+Ga4DxsINAygETHra4KqEtrszagVXZBoxb6ieb wt29iYIMUK9jAhpIJcfrOQOFq7H92H6VKa99khxOVq8tybzcxihDFa0zbmd1ZVJQ 3weLsk1dJFUHCtUsOmGCSt9k6K0riAJGK6fj8E8/QMhhi0ug1Jd6dEUPbTv6ePVC WDzLm0To98oDuC09mHVfvMHeqNdc8vZvW5ryX1dRLPYNyAddpD+D2JxZZ39gqcq1 GQ7DuoqGB7WfytpzgkBJUVoXh8s72fIueXO/J3E90bqPR5YZWE5yMPSovBU5HIQf YpQsnZOk3YD4mkIq1ZVxXhoF/gVN1uLvOrfQtmDHQLpNsR2+lTetL/XAkI97bYXE qmr8kVhiJxJqy4BSw0P+/58E3hXZ5VjegCIXEIT7QFckLKjcQTqewUxcoIxtOaC+ /wctMxH7DfbNtyua6Sw3IQMVfCH4BkOJuFsTCCer/c7uuwderizOhRWrGPQPOjXU pfw0s+kw4AeqToYvRGRFwrDD1LMCxihtoyhpYn36NCIaJteTDKQHoIaaKhChJ3EP LuY7XOyH3wvZGB6wLntMnkyP1Rk5NlIdLjkjaal7xawsQR+qNp6yXJ1wMJ5pkEHg 7oKj2iywRDtGWlNv7OThaHeAkd+RKNuxoI+QJ2FQelApbL2Un959jRQ09qJiXcc= =2jwd -----END PGP SIGNATURE-----