-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 21 Feb 2016 04:34:40 +0000 Source: chromium-browser Binary: chromium chromium-dbg chromium-l10n chromium-inspector chromedriver Architecture: source i386 all Version: 48.0.2564.116-1~deb8u1 Distribution: jessie-security Urgency: medium Maintainer: Debian Chromium Maintainers <pkg-chromium-maint@lists.alioth.debian.org> Changed-By: Michael Gilbert <mgilbert@debian.org> Description: chromedriver - web browser - WebDriver support chromium - web browser chromium-dbg - web browser - debugging symbols chromium-inspector - web browser - page inspection support chromium-l10n - web browser - language packs Changes: chromium-browser (48.0.2564.116-1~deb8u1) jessie-security; urgency=medium . * New stable security release: - CVE-2016-1622: Same-origin bypass in Extensions. Credit to anonymous. - CVE-2016-1623: Same-origin bypass in DOM. Credit to Mariusz Mlynski. - CVE-2016-1624: Buffer overflow in Brotli. Credit to lukezli. - CVE-2016-1625: Navigation bypass in Chrome Instant. Credit to Jann Horn. - CVE-2016-1626: Out-of-bounds read in PDFium. Credit to anonymous. - CVE-2016-1627: Various fixes from internal audits, fuzzing and other initiatives. - CVE-2016-1628: Out-of-bounds read in PDFium. Credit to anonymous. - CVE-2016-1629: Same-origin bypass in Blink and Sandbox escape in Chrome. Credit to anonymous. Checksums-Sha1: 2d67db4b1505b8fc59f8dfaa38f39d17f1bf835f 4067 chromium-browser_48.0.2564.116-1~deb8u1.dsc 1aed24fa811a762bd42e1107de3cebee933c3031 432139308 chromium-browser_48.0.2564.116.orig.tar.xz 1c5aa0f3c1f3571d0943750e1e6e96f8fb604126 179736 chromium-browser_48.0.2564.116-1~deb8u1.debian.tar.xz 7387899a8fe38645eccfc060b583270421ade587 39322132 chromium_48.0.2564.116-1~deb8u1_i386.deb 07d964d4bdff255be75f9c7498410ab5bc4db93d 7175210 chromium-dbg_48.0.2564.116-1~deb8u1_i386.deb c8a6a09dc5b7589701b800204ccf6628e42e1a37 3176036 chromium-l10n_48.0.2564.116-1~deb8u1_all.deb cf9440b563392533ad78b9f45017c52a873af8d6 1117076 chromium-inspector_48.0.2564.116-1~deb8u1_all.deb d690f495253649c9a3e70549eb639d336b92f5ad 2432980 chromedriver_48.0.2564.116-1~deb8u1_i386.deb Checksums-Sha256: 5936ab96c41ce89a21cac2295a8b40cfe7fb685a2b605794f52aaa8fa9e5af70 4067 chromium-browser_48.0.2564.116-1~deb8u1.dsc ce3c052e13b6c665bf9ca1ce3d5538f94861196b8ed3cbd924a2c44d2898c845 432139308 chromium-browser_48.0.2564.116.orig.tar.xz 4f028ac1feda03663265f868e7fd9fdbaa9676a50a3b0c94a32908c4be4e69ec 179736 chromium-browser_48.0.2564.116-1~deb8u1.debian.tar.xz 1e3ab650f4126f401bd83ac522c513df8e3cc539ffaec6daed70e643718ee093 39322132 chromium_48.0.2564.116-1~deb8u1_i386.deb e7e1b623a6b1e4f9a29ce6282b2e52ad051a79fbcf0a42ac9150321175cefc57 7175210 chromium-dbg_48.0.2564.116-1~deb8u1_i386.deb 91de3028561cd3d38a31695aa38ea6fca288e0d25532d854d0750b347f0c8d5d 3176036 chromium-l10n_48.0.2564.116-1~deb8u1_all.deb 503d2367082597d0ed1a86b61ef8a1336594b37f54d2b72f71d5ba9812e9124b 1117076 chromium-inspector_48.0.2564.116-1~deb8u1_all.deb e45c0136a5a09ebd923152046a1f59bf9f2c92cd7fd2eef574d2b0226694daa5 2432980 chromedriver_48.0.2564.116-1~deb8u1_i386.deb Files: bafa6753e0640e92698cc1bd03f80f3b 4067 web optional chromium-browser_48.0.2564.116-1~deb8u1.dsc 0ecdb745966669f9762d5e92837eb8ce 432139308 web optional chromium-browser_48.0.2564.116.orig.tar.xz ef4fc6bc09986742d5d0d895edcd6fda 179736 web optional chromium-browser_48.0.2564.116-1~deb8u1.debian.tar.xz fa6d34b22e83c991980b15559b16f06b 39322132 web optional chromium_48.0.2564.116-1~deb8u1_i386.deb 7dbca0bf0dff8e02664a16a21e8311d1 7175210 debug extra chromium-dbg_48.0.2564.116-1~deb8u1_i386.deb c59da773b65c9a3faec2804bf9f641ff 3176036 localization optional chromium-l10n_48.0.2564.116-1~deb8u1_all.deb a3c715293fd21ff948da3e899c5ebc81 1117076 web optional chromium-inspector_48.0.2564.116-1~deb8u1_all.deb 4411ca7ab66b1a817ca1ff87f135e636 2432980 web optional chromedriver_48.0.2564.116-1~deb8u1_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQQcBAEBCgAGBQJWyWYUAAoJELjWss0C1vRzaGcf+wSX1O+Qo+oG3b2aTUUKMKf3 OvrN9N5jKqLHjPTO7Ify01+IP2OtpaYFdhwimqo9yH2MEKAIOy3VrJbFj1FLQqnK s3r1giYBl8ce4776qJI1UkKS4LT5Wwd+qL8wHbQ1o5s/T8Jx9rUZxBU4iVDZzSg8 efbOMLrsHPPTSfQbAqqNTePjoW5wfvGb661PIj2oHFBOy9utecIdTr5BdeHxU/sS TaX/0pixHbMvUEzJYXNoJRNzFWBxTTCt7aErRpY95bLwuFfDMiuwgpgwOzBBPO4x bxAJSWVNXr13YXhJLeA9A2QGpripA3/UArPOK8PLfQbDKzvscDm2oFShK4SVXS1h 1UkZ+brqAV7EeJwlw/uG+kOvqhyPXzr2PBcihHd/5Hm6Nm+VQiaeA5lsn29otY60 yCbRnr+cVldKdz66MD/OeA3mIi+G0eXBNA8/QseKyzHemFOFedkkq4fDNq3aMuIQ OsaNNrGxdf42WRoKs/8zg+lQnCq74+EAwvXZ6KIrwXRslBaq1+vwO+djEGe0Uvkz LzxMmLnm5h89jDg1Nde6UN8CH/ujGKHQ8u6Jkv5fzHE9PTyAJ8ID7KAhCnizrzlb huzs/4UcurbS4Gd6h/tlETP0/Lpd9/+5dAu7I2qf1iCdGwz3qLP0jp+dJNpyUddp y8gnBhWsB+TfZckjIo1z2Gsr09z81s9rEFqYkXwK/pN+9fpxcSG6zLnWTGbVDTb2 fq+8HsnXDAI6Cy1ydonR/1Wj6bHOHliH7RVA7fex3lngxRAJ4kB1JViKZi2orVvr yjGJDpaxsVcBC82fuHV4LlARAit96U87ZbE6QLge7+0yNxdNqzyBn1zm4/BKodtP APdbjLq30zUmBw1vAWZj6pE8jhF0CBVP+2uTzttwvQRrBD/uSl7fsWFoZMANlDGl Ed7syoaS/9pwBZ6onbLmnqHKekBT9W0MN5hhQzkoceuxWTPFNN0EgteB5rz8s0UT 2vPbxazYxvYQaUtR/TxTd7bW/kjMGTki/8EHEMHIrZAxlQp2/eYAfmoNmeLmDz+S 1MEJleRXeHZ5WG2J7cBQ7xtkIHXajI5RLiV6NmzKrwWUiz5YGiprt3wYhMQcR4wN eh3KzyJ+VkMVr/6Ad0pxXqPQ7Cf+4KGkMpUO7cBk/DIM5RrY+O9OHAae3/5mygCY cEkMDheUUMCtEX2vi9IGPgEcjpjreDi65bqGAaybuT9L59Fo17hmq6mxklvmb5Zj n6qyoiotHRmJpd/TnRPRcXFxJDyJEc7tgypFYNzyW5350DmqauzWEbJuOd+Wb8MU i90k3dMgpfANgf1/RHAU5fM/h3lW8zjMwrpM84uhigo0c0IW3jXTE4YhL9G7NWU= =vSX7 -----END PGP SIGNATURE-----