-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 23 Mar 2014 00:42:47 +0000 Source: chromium-browser Binary: chromium-browser chromium-browser-dbg chromium-browser-l10n chromium-browser-inspector chromium chromium-dbg chromium-l10n chromium-inspector Architecture: source all amd64 Version: 33.0.1750.152-1~deb7u1 Distribution: stable-security Urgency: high Maintainer: Debian Chromium Maintainers <pkg-chromium-maint@lists.alioth.debian.org> Changed-By: Michael Gilbert <mgilbert@debian.org> Description: chromium - Google's open source chromium web browser chromium-browser - Chromium browser - transitional dummy package chromium-browser-dbg - chromium-browser debug symbols transitional dummy package chromium-browser-inspector - page inspector for the chromium-browser - transitional dummy pack chromium-browser-l10n - chromium-browser language packages - transitional dummy package chromium-dbg - Debugging symbols for the chromium web browser chromium-inspector - page inspector for the chromium browser chromium-l10n - chromium-browser language packages Changes: chromium-browser (33.0.1750.152-1~deb7u1) stable-security; urgency=high . * New stable release: - High CVE-2013-6653: Use-after-free related to web contents. Credit to Khalil Zhani. - High CVE-2013-6654: Bad cast in SVG. Credit to TheShow3511. - High CVE-2013-6655: Use-after-free in layout. Credit to cloudfuzzer. - High CVE-2013-6656: Information leak in XSS auditor. Credit to NeexEmil. - Medium CVE-2013-6657: Information leak in XSS auditor. Credit to NeexEmil - Medium CVE-2013-6658: Use-after-free in layout. Credit to cloudfuzzer. - Medium CVE-2013-6659: Issue with certificates validation in TLS handshake. Credit to Antoine Delignat-Lavaud and Karthikeyan Bhargavan from Prosecco, Inria Paris. - Low CVE-2013-6660: Information leak in drag and drop. Credit to bishopjeffreys. - Low-High CVE-2013-6661: Various fixes from internal audits, fuzzing and other initiatives. Of these, seven are fixes for issues that could have allowed for sandbox escapes from compromised renderers. - High CVE-2013-6663: Use-after-free in svg images. Credit to Atte Kettunen of OUSPG. - High CVE-2013-6664: Use-after-free in speech recognition. Credit to Khalil Zhani. - High CVE-2013-6665: Heap buffer overflow in software rendering. Credit to cloudfuzzer. - Medium CVE-2013-6666: Chrome allows requests in flash header request. Credit to netfuzzerr. - CVE-2013-6667: Various fixes from internal audits, fuzzing and other initiatives. - CVE-2013-6668: Multiple vulnerabilities in V8 fixed in version 3.24.35.10 - High CVE-2014-1700: Use-after-free in speech. Credit to Chamal de Silva. - High CVE-2014-1701: UXSS in events. Credit to aidanhs. - High CVE-2014-1702: Use-after-free in web database. Credit to Collin Payne. - High CVE-2014-1703: Potential sandbox escape due to a use-after-free in web sockets. - CVE-2014-1704: Multiple vulnerabilities in V8 fixed in version 3.23.17.18 - High CVE-2014-1705: Memory corruption in V8 - High CVE-2014-1713: Use-after-free in Blink bindings - High CVE-2014-1715: Directory traversal issue Checksums-Sha1: 6b91cca19c8c51df6f716021e85da1b5a2ee0510 4370 chromium-browser_33.0.1750.152-1~deb7u1.dsc 3789e1c8429a5e31dd4e9cc9cd8c9f1bb773057b 670022764 chromium-browser_33.0.1750.152.orig.tar.xz 0b98a2bbf0d9cbf8ffb9dfcac1d9832233760cf9 257770 chromium-browser_33.0.1750.152-1~deb7u1.debian.tar.gz 6df2e8ef17ca68753d4611d2eb6156752226fd0c 163116 chromium-browser_33.0.1750.152-1~deb7u1_all.deb 7d63d370c54a0cf717e2fe6a0690437b88668b36 162462 chromium-browser-dbg_33.0.1750.152-1~deb7u1_all.deb 50ef856f4bb916383fe1510dab5061ecfbf5073b 162586 chromium-browser-l10n_33.0.1750.152-1~deb7u1_all.deb 71617000fa875c7c73340e3c393b95836b70d50a 162412 chromium-browser-inspector_33.0.1750.152-1~deb7u1_all.deb a021e61891788e060de66f2dd2a017f8ee1e1ee5 3047064 chromium-l10n_33.0.1750.152-1~deb7u1_all.deb 99b12ebf5c891703b9567f9d9d1cf52b06b03ae1 714650 chromium-inspector_33.0.1750.152-1~deb7u1_all.deb d9f458b7a408101320f7358105dbcead9d588450 53867576 chromium_33.0.1750.152-1~deb7u1_amd64.deb 66f116521a987fdf82af1b839c328fe7e065276e 538332696 chromium-dbg_33.0.1750.152-1~deb7u1_amd64.deb Checksums-Sha256: 59dbfad552080f6fa633c81a3e47246edd35038b4e652c89a755abd170a0708c 4370 chromium-browser_33.0.1750.152-1~deb7u1.dsc 55cd24a70f8a4bca381b9e9dff6818aca0b38a36cfc8586f6ba8f2072d2694b9 670022764 chromium-browser_33.0.1750.152.orig.tar.xz 5bd6fe8260dffc67941289140a1bff4e17576cd4663cc8f82acdb75759de9eb4 257770 chromium-browser_33.0.1750.152-1~deb7u1.debian.tar.gz 78c9afaff97124d22d5a94bf91dd2696a920724540ec4b80eef2426ccea8967f 163116 chromium-browser_33.0.1750.152-1~deb7u1_all.deb d9f9279d3a002356273739559f519f4737351f2d1be1c11e0f14b23dffd52b24 162462 chromium-browser-dbg_33.0.1750.152-1~deb7u1_all.deb a3347bbc9419454ee74a2eb28eb96021d490bb3720425e03a9feb3832b344eb5 162586 chromium-browser-l10n_33.0.1750.152-1~deb7u1_all.deb 05941f26b57325ff28a08f9870e16508b3db783b34907f1570d529c30294dc05 162412 chromium-browser-inspector_33.0.1750.152-1~deb7u1_all.deb 0ea7a2cbae71db6dc974dbd6bbe8c9ff8e33396f47224515495c232544de6b6c 3047064 chromium-l10n_33.0.1750.152-1~deb7u1_all.deb 736eb829f7621596ba72453a6814eb45b0465a2f62225539695b160c80abe9ef 714650 chromium-inspector_33.0.1750.152-1~deb7u1_all.deb d030d93966040c0d79f27d0032638ceaaab7fced2e7a529b618d89d38cdf75a0 53867576 chromium_33.0.1750.152-1~deb7u1_amd64.deb 6f56712ddaea57ab0229621703e3f0e765c8357c7337047ac037590606780788 538332696 chromium-dbg_33.0.1750.152-1~deb7u1_amd64.deb Files: 269260b4c5caf1d9804594c2a2758af3 4370 web optional chromium-browser_33.0.1750.152-1~deb7u1.dsc 15f5ac11068064206335942bb1e1b9b7 670022764 web optional chromium-browser_33.0.1750.152.orig.tar.xz 04775cfefab889a8b49d80c45defdea8 257770 web optional chromium-browser_33.0.1750.152-1~deb7u1.debian.tar.gz 820530a32649c519d88dd426a6a0201b 163116 oldlibs optional chromium-browser_33.0.1750.152-1~deb7u1_all.deb f6b8d58aa717208c2daddec8133a8176 162462 oldlibs extra chromium-browser-dbg_33.0.1750.152-1~deb7u1_all.deb 597289c8e55806a8225f54bc4afb0a96 162586 oldlibs optional chromium-browser-l10n_33.0.1750.152-1~deb7u1_all.deb 3dd0f40f7c9ed755b9f114acb3667514 162412 oldlibs optional chromium-browser-inspector_33.0.1750.152-1~deb7u1_all.deb 1dcbb613b4a15ce83067a34f794f1d32 3047064 web optional chromium-l10n_33.0.1750.152-1~deb7u1_all.deb 34e69da8bdbb53510abc0f55ad74ff3e 714650 web optional chromium-inspector_33.0.1750.152-1~deb7u1_all.deb 024840b0ebcbbb906ab0e0d5f8ff324e 53867576 web optional chromium_33.0.1750.152-1~deb7u1_amd64.deb 751cc76ee952c516b838e3136149a9dc 538332696 debug extra chromium-dbg_33.0.1750.152-1~deb7u1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQQcBAEBCgAGBQJTLldSAAoJELjWss0C1vRzp+kgAKR8XeLQabAKMkifYvtZRHl9 ZcyNSg7nbCVgiWT6r/PSPU0UDDwwxnV4aW1M7EPjMPyR7XoFElFl47+S/2vT70Qd /Lhkc+/3wXiKBvDGD+6T0xvAYwIUirjA4MhjIXlYYEX8LehmI79vevJr0rGJ2GGA +Za5mPoew9+pWOunsNqkR50QchBIsmApvVRHpr5EkV0oJTcINDkdyw61hztuO3aC yE3Cd/21wcGHKtnHmiCCcww8uqC4tSrDEuBDQodgfyVha5jpTsB5LIWAG2wVcloJ jcuQJ+hBEMO9yR7YYUmHrDNjjoLRcHzfCfC9bFgMJ91IgSxyg8W4DAgGvOaM/Ryo lU0+SbuGhT3mw78seSJmBgsevyjV5EyavWJ1+ox/7xdL+ZKbucFVUVq2kzz4A2Wz xfg3teYUg56AIFDJSKfIDYRlFIsbG0cZlLgwpEl4wF09fT2xVQSRiYt0pCSrQmkL 193jYg8iGsfRujdhiJJ2Gz62x0oMq8zxGd38EuGNso9IhJoDGh8G4lkjZIpD1Pd2 6hB5o9AfDO0rM2zztYNasK+RmvEj4f4PLVSNcEdue0asVAAeYCHE5R81jWXIaPwV KkKO0Aqw4BMi3uN8UGPGql81Ilbc5T6py+gCEcYnf0dEV8xRmwIarh0dUUjlvSGN 20NZzLK88rd/e6Y2o+e/PCZOGIrzJLa27QG9LLUQekQyiJSl+5/ZpGFM4ZSGKXd/ 3bmOJPDt9jDNzrhhEsHxn/nRNgeVaE41GBNJRUegusRsZbrA1WO6RgAybMIi+8+o EGap9KH/FqLyB74HyIGyNdYnY+DmtN+eOMQdHZRQtQp5yA4bRqIKyX147BQqw/ot JDCJMonjoXnY71Hiz0VSCEOjROoEYwSOn3VoRsQRzjcxFfXBkJpcLc6AyxSYr6bW zicIVTKiC5gu88vGaUKVd3ZhpyX+18urZ/rFfldgKW23yMHuFT1b9F9DvYrXKU7R 3I8gZis33L/0trjF1n2bOzZUFM2PX06IweDzuvdseUlN6NBTpjhiOBu2PalbTpWR 6AX6JjF9PNjnbfj3mPeGcWcZCFUXoNMSC70Jd0VqunQFYmtf5Kx59Za/+Se1dBAY L76u/oCB38sUw20FqXr0jOZIUsXDiDE8IVgMlOGejqLtUKuEZVyYMkUbm4ZVRayu SDvpMalx7QpMpP0N/+b+59BcWBEiXXtbYwT5SrD5el4TJrk0Q1JW2h4ke5axKuxd Cpget7gDelgQhyDjp7zpuN5taxGUrtBCWfudBNjz37WWgu+VT0HNhVo6YQrqXqin XKxtCN0DzKUTGj84j1HLNP4R6/pbVFPGD/JjkCXIOGTq0gBO23XrsdP5vf1W4y4= =Jwmb -----END PGP SIGNATURE-----