-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 08 Dec 2015 02:09:49 +0000 Source: chromium-browser Binary: chromium chromium-dbg chromium-l10n chromium-inspector chromedriver Architecture: source i386 all Version: 47.0.2526.73-1~deb8u1 Distribution: jessie-security Urgency: medium Maintainer: Debian Chromium Maintainers <pkg-chromium-maint@lists.alioth.debian.org> Changed-By: Michael Gilbert <mgilbert@debian.org> Description: chromedriver - web browser - WebDriver support chromium - web browser chromium-dbg - web browser - debugging symbols chromium-inspector - web browser - page inspection support chromium-l10n - web browser - language packs Changes: chromium-browser (47.0.2526.73-1~deb8u1) jessie-security; urgency=medium . * New upstream stable release: - CVE-2015-1302: Information leak in PDF viewer. Credit to Rob Wu. - CVE-2015-6765: Use-after-free in AppCache. Credit to anonymous. - CVE-2015-6766: Use-after-free in AppCache. Credit to anonymous. - CVE-2015-6767: Use-after-free in AppCache. Credit to anonymous. - CVE-2015-6768: Cross-origin bypass in DOM. Credit to Mariusz Mlynski. - CVE-2015-6769: Cross-origin bypass in core. Credit to Mariusz Mlynski. - CVE-2015-6770: Cross-origin bypass in DOM. Credit to Mariusz Mlynski. - CVE-2015-6771: Out of bounds access in v8. Credit to anonymous. - CVE-2015-6772: Cross-origin bypass in DOM. Credit to Mariusz Mlynski. - CVE-2015-6764: Out of bounds access in v8. Credit to Guang Gong. - CVE-2015-6773: Out of bounds access in Skia. Credit to cloudfuzzer. - CVE-2015-6774: Use-after-free in Extensions. Credit to anonymous. - CVE-2015-6775: Type confusion in PDFium. Credit to Atte Kettunen. - CVE-2015-6776: Out of bounds access in PDFium. Credit to Hanno Böck. - CVE-2015-6777: Use-after-free in DOM. Credit to Long Liu. - CVE-2015-6778: Out of bounds access in PDFium. Credit to Karl Skomski. - CVE-2015-6779: Scheme bypass in PDFium. Credit to Til Jasper Ullrich. - CVE-2015-6780: Use-after-free in Infobars. Credit to Khalil Zhani. - CVE-2015-6781: Integer overflow in Sfntly. Credit to miaubiz. - CVE-2015-6782: Content spoofing in Omnibox. Credit to Luan Herrera. - CVE-2015-6784: Escaping issue in saved pages. Credit to Inti De Ceukelaire. - CVE-2015-6785: Wildcard matching issue in CSP. Credit to Michael Ficarra. - CVE-2015-6786: Scheme bypass in CSP. Credit to Michael Ficarra. Checksums-Sha1: 74ee6cee1f02c402cc7b16853750f17e2d57aba4 4060 chromium-browser_47.0.2526.73-1~deb8u1.dsc 29ebf7f5e92435be3debe63529d47b6b9b12a9c9 394400368 chromium-browser_47.0.2526.73.orig.tar.xz 47529485529e779e133f32e8f0321f3f9bd47a7f 179328 chromium-browser_47.0.2526.73-1~deb8u1.debian.tar.xz 5d8e32f193119f3c1ba29c6920d701f5537970e0 39388278 chromium_47.0.2526.73-1~deb8u1_i386.deb 10129c8c046186b720d7f58da55234f954ab2e9e 663643070 chromium-dbg_47.0.2526.73-1~deb8u1_i386.deb 67c380493667d029fd9045f4b224d65f6081497c 3181778 chromium-l10n_47.0.2526.73-1~deb8u1_all.deb 4a11f5ad45b94eee3bd4f8afbbd032152b6a2a77 1097452 chromium-inspector_47.0.2526.73-1~deb8u1_all.deb 89a3026454fb90f29e3b339e6b99495bbaaec101 2462492 chromedriver_47.0.2526.73-1~deb8u1_i386.deb Checksums-Sha256: 05668550d41466e04a0648060a7375ab3d2816de262cdfcb1fb0b093255ee215 4060 chromium-browser_47.0.2526.73-1~deb8u1.dsc 1a2dc013932c237eb55528281f7ccfa7c775b6f1d357d8ad1235e55cf4fa7fbd 394400368 chromium-browser_47.0.2526.73.orig.tar.xz 47a1eb22fcc5d175d8bf08d0d8732f73a4a9dec0650285eba4dc6ac2ae80fb6f 179328 chromium-browser_47.0.2526.73-1~deb8u1.debian.tar.xz 6bff04d2b7f74048b7caaf1efa3544a307ead98984689f05aa59c1f09643f4a5 39388278 chromium_47.0.2526.73-1~deb8u1_i386.deb e1b0f6b8d5ebc29bbaec1a3bd599d3443b2703fb858807d4d37cc13b7c807cf5 663643070 chromium-dbg_47.0.2526.73-1~deb8u1_i386.deb 863a88d7d7e5c08973d0ce23b2109e7fb1c0a8baec74e9cec357ac29aeb6739c 3181778 chromium-l10n_47.0.2526.73-1~deb8u1_all.deb 9ce537a69f9dd0a8d649e9adf42b7c4b00d73e41033d466fd98eb1c97ee6be77 1097452 chromium-inspector_47.0.2526.73-1~deb8u1_all.deb e7bf3e2773e75dab9cbf9cfea67e972f023b7f392fcdbcc56cdc99dd9c15ac0f 2462492 chromedriver_47.0.2526.73-1~deb8u1_i386.deb Files: 7c95ad208d5fd7a66e4536695665551f 4060 web optional chromium-browser_47.0.2526.73-1~deb8u1.dsc b77406555fb4aa7b9331734148580915 394400368 web optional chromium-browser_47.0.2526.73.orig.tar.xz cda856a606131670b8bf35f071a17f40 179328 web optional chromium-browser_47.0.2526.73-1~deb8u1.debian.tar.xz 4907d83c5f46dc2e274db9a338b12a4c 39388278 web optional chromium_47.0.2526.73-1~deb8u1_i386.deb 25427931b9e5ee92ce025da4e198bbf9 663643070 debug extra chromium-dbg_47.0.2526.73-1~deb8u1_i386.deb 1df1c077cbc0aaa833268cd507f2c2ef 3181778 localization optional chromium-l10n_47.0.2526.73-1~deb8u1_all.deb 1a7d9d5433fa12477dcb71ed1e3c0b17 1097452 web optional chromium-inspector_47.0.2526.73-1~deb8u1_all.deb 0e0dbeeccd076e7414a2bc64d3a7ef85 2462492 web optional chromedriver_47.0.2526.73-1~deb8u1_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQQcBAEBCgAGBQJWZlnYAAoJELjWss0C1vRzHJgf/1Q7nh3gqUT97aYjQIXTdaCV YYhuybGu6TXP1VGFPPZpIwRaIYR+QoR1D+THsAuTi9uHj+oP0yRJtTLKVY/5sYL8 3i2g5pv3dXPTwFZKPSOEY40qefm/Fr7AV9jKwjfauOrhPlXqRaTTZqpC2rwNh3mg atPtwTuL21KIMXOM4mbvyFtxLXFqVPFOMYqBRaNHZ2wA0tja030xeTEgrqEvQsTa RK4ERnHhkqgENZF3L2i+tzonRs1wTcKknANNicdbZwjgc3sretOs4DNSkHW9KhNQ bamMeGL+hhK4RxxB9/HRYqlLO8MYShE0EUEyNMuVa/7Hj2GbD3nb7t4M9/N47dPT ColfV6J2CQTS0aP08LFN27smVflY0nW3WnVyfp5aaQnRwhiqAHEUs4F1inPtH5jg a4Scu2JaCNAGy2Zupw2r5xjJ38o5cCovJXBOFVtoXzBh1hDBDomqgZpdlA49DgSU d/fqIqvG2I2EoHrdyekPovQ9Xj3Yew4gsI+7U3yJe19H64MsRR1nYXETHkaluFjn 8iL70kywjPBGUq7ftPuH/x6Bqaty21pN1XOrE1177A0IikT+N9lbPt0rAUhDnNw/ 1THCatdJIXJ6NQszcdLb6pAqH555SDmD5Mby8RKCXaWlr1Obr6XMTGpuKL93OS34 hhZNSb0XHaE/4j8e3tWN4swz3JJch1rjr1GiiCMzRkpEhNPAEqeh8037uI+nmL0Q 492ZY+D07nFtWintVtNcixfDsmEAxMO5ccI6HoYLN6E0GnM1WSVZte3rhCtmXtOq wGVos762/XpbVglb+0iOvvT8LiT6tO5RIidOaPnHaP4H+JAqgU8129RgU/xxD66v pMkHujHgRVB6gil+B4uVQXRQ6HjhgCSQYt+elsjKEnn2WlKMxghrkfoQmpijdo5t lNjxyouVYH4A9bKKK37jUltBtbK0T+SQgb/fc7mjhbhEkz4B7Lp5n0vJqnORFjkW 8egpopL1sXE9K6SBS81/wDjncYhlzfiqiXRgginyy8nyYLA8JuBXs6CIYDvpeSF0 SobTj9ijUTuo4lvwRyAjDtTLI5DjSDGVRR6KZT8muGFMnv4bHkgl7w1jKmHYVQnK 83fgTDDCYphJsgm+fTTWWoYVATZn58+h6zySb9V4fPtR6Uacrd82D8c4HZBXFQVI h7Pe8fXWX5/l/XTMbAsH5p65ryc/b/lOZ70gxvZNNc2LQB7dwatZ2mW2McJJJ+CW WfX+8AsxWxjalrB/CiAkk2nAdrJVpHDIw2QjqD00TWuVcEZQAqkwdKp4Sz8tuuxy smFVxgXIDnavhrRFUh8B1kuQgnFXHtBygzEBQ09zQEjyiJFwRcI4LXN5dSYG0bY= =MM27 -----END PGP SIGNATURE-----