-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 14 Apr 2016 23:47:48 +0000 Source: chromium-browser Binary: chromium chromium-dbg chromium-l10n chromium-inspector chromedriver Architecture: source i386 all Version: 50.0.2661.75-1~deb8u1 Distribution: jessie-security Urgency: medium Maintainer: Debian Chromium Maintainers <pkg-chromium-maint@lists.alioth.debian.org> Changed-By: Michael Gilbert <mgilbert@debian.org> Description: chromedriver - web browser - WebDriver support chromium - web browser chromium-dbg - web browser - debugging symbols chromium-inspector - web browser - page inspection support chromium-l10n - web browser - language packs Changes: chromium-browser (50.0.2661.75-1~deb8u1) jessie-security; urgency=medium . * New upstream stable release: - CVE-2016-1652: Universal XSS in extension bindings. Credit to anonymous. - CVE-2016-1653: Out-of-bounds write in V8. Credit to Choongwoo Han. - CVE-2016-1651: Out-of-bounds read in Pdfium JPEG2000 decoding. - CVE-2016-1654: Uninitialized memory read in media. Credit to Atte Kettunen. - CVE-2016-1655: Use-after-free related to extensions. Credit to Rob Wu. - CVE-2016-1657: Address bar spoofing. Credit to Luan Herrera. - CVE-2016-1658: Potential leak of sensitive information to malicious extensions. Credit to Antonio Sanso. - CVE-2015-1659: Various fixes from internal audits, fuzzing and other initiatives. Checksums-Sha1: 2c3d0996d9cfe3907e46a142e00221235852eb7c 4072 chromium-browser_50.0.2661.75-1~deb8u1.dsc 6e41df47d63bbb5bde0d8e158ab5a65a02bae0a7 529456064 chromium-browser_50.0.2661.75.orig.tar.xz 0f170494e19c2abb9b6e4003bd5e611925f244df 180224 chromium-browser_50.0.2661.75-1~deb8u1.debian.tar.xz 741fe8c5fb9f46baccc92cfa6a508044ae9ac743 40092484 chromium_50.0.2661.75-1~deb8u1_i386.deb 94acbb3854a2e41682babb5b26588716bc167d9e 7314080 chromium-dbg_50.0.2661.75-1~deb8u1_i386.deb e34926f5d585a6b0c6e544e6b93f45e7152e391a 3082922 chromium-l10n_50.0.2661.75-1~deb8u1_all.deb a0a53eb466adf03bbabaa772032c8d6d8681b3ff 1301236 chromium-inspector_50.0.2661.75-1~deb8u1_all.deb 172a40aeccd03ef722f3836745b1bc61cb96493b 2557672 chromedriver_50.0.2661.75-1~deb8u1_i386.deb Checksums-Sha256: bc5364084aaf8916ffbf268612ecf8c44757ab0e07474ec2f8bd11dbcf694d84 4072 chromium-browser_50.0.2661.75-1~deb8u1.dsc d3d44abc59fe923e0a55032b61253af9438de019699aad863a3f3c87e903fd7e 529456064 chromium-browser_50.0.2661.75.orig.tar.xz dc6beda9fc823da798102f3ba8c15f9dd4dd03d9d5a51d28518df731413780ac 180224 chromium-browser_50.0.2661.75-1~deb8u1.debian.tar.xz faf72563171100bf5972e5e051629739881df27be015f5cdfdc55c1ff9df3458 40092484 chromium_50.0.2661.75-1~deb8u1_i386.deb ff4120172f2445ccc1a5ae4fdf40ac0256c77b1941ea262c0db9572bbb1be541 7314080 chromium-dbg_50.0.2661.75-1~deb8u1_i386.deb 0808e178d0438533ff6726a5270ec804b0bf1595a8c23fd7d119ebd15a50de5a 3082922 chromium-l10n_50.0.2661.75-1~deb8u1_all.deb c318fa0f126aa7e93675a590ce223bddfc4122663a652db65f7085a0aca935d6 1301236 chromium-inspector_50.0.2661.75-1~deb8u1_all.deb 6573fb6a33b547e777c2debdfbaeddb40986732bc8ec6b47587f85e2d519c34d 2557672 chromedriver_50.0.2661.75-1~deb8u1_i386.deb Files: a39b43231435f68b6af1d887234d4e94 4072 web optional chromium-browser_50.0.2661.75-1~deb8u1.dsc e6db07cccb6cd6bf4090ce2dd2ca1bd5 529456064 web optional chromium-browser_50.0.2661.75.orig.tar.xz 644828f603d8e05e398be77561991cb3 180224 web optional chromium-browser_50.0.2661.75-1~deb8u1.debian.tar.xz bf6fe6ecb97a8ca70d699ddaa044e482 40092484 web optional chromium_50.0.2661.75-1~deb8u1_i386.deb f22bfe2ba6a5a611b57d81d5565f801c 7314080 debug extra chromium-dbg_50.0.2661.75-1~deb8u1_i386.deb bf30bcd32b4fd5d15c599ea63e26ba2e 3082922 localization optional chromium-l10n_50.0.2661.75-1~deb8u1_all.deb 9898d1b7ca13963e4d9ee619dcc1e9cd 1301236 web optional chromium-inspector_50.0.2661.75-1~deb8u1_all.deb 46bc5aab8829cdf8f1bbc5e692b39a42 2557672 web optional chromedriver_50.0.2661.75-1~deb8u1_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQQcBAEBCgAGBQJXEHvIAAoJELjWss0C1vRzYbsf/R7lY3dlhYv6e6oSpaH80icU jSdLJRXwy0curaHC2CADuU6upuY+32Nvs1ECf71OFQqLwQ+vC4hquZ7F7xty1/JG IoXcrTEFOm47UsZwNPPcGOscXtBsHuCgC+6veBhcQ4xvPOrJ5M28ze1bMrz0hOex bkp2F2vrVDWknx2L4h/zazYARXFkSj+jrM9h+MSUWTXkllmAvAQaJ2iokFm0z6Am YcugkqIezguEYJgPjKnmsJf/Y3RjT+2jUJmQRdRjpysUEnCgI8oLApgssFl5ySUO COcsY7fKMZEskcKtHyhSxbOuhkWgTPS7oCt9IyAwnh5fLWamxn2cgHn1ls6dKgLK UmifSkpw08x63MTNhorn1VhbGa6XMCi2P9yAWW8N50BF1+L3wINpd8OTrYRrsnkB tzdmfEcXv5hOpz3DPZjzUgSX5URmbSO3uCxI9pcG7y9EPE5coSOJT2JqDHw3SFZK ViEy+punPEG6r9AZ4a6Zq+lpgK6s3y+yfzQmM7CpgMh4bAHzOsBPm8+8ZbrbYr0m 1Em0sYBq7JoRVu4fHW/9z+GUKyg6ul0d5nIOQ2ZLonQEhIEkX88kZPLzSELsGSw6 ub+AhauVqDsnAelNH6e+RLOJDskZa1NRkBtI59qbyJmzQQoP2k9LFGOgqgnTENtw lSm2kj7qvHz5+yCNKovb0wjuIcxmtHojWcnZh0FlWom0qXug026NwmMN14Ip2bj3 jqu1t8LL+XacBP62SIlGVkvsy4vcpLX0Hy5JYz97Eksk/GSehKfZx2n5j852xCqZ CJdcm8rDvlUuadx9PHmKStWkdZ+0T7WxaSIQNEk/Maa2FPrK/UKiNUf82UOFCiZI zdO9Ui5fjPNNDvZ3wF4EKDdMOEdO7p5Pe/US6lQKdx1Ou4aiqdoOnCrd32+hk0M3 Ocva11t5cV/eSRwvD0QbnE4eq+7TkzUaCIjSc1JSeKnHA71DGIP8ftcxMdLwpNOw m/ziOuXBbHWglT2sqNehCwNBEtRJt0dSDA9WcyMw0hLhjjzAJBC5s+J1++I2NfhP 5gEvXgSEBt8CGfFA8Q1Tg4eBVRZB9/FJ6TtfR2T25FEcUS6k69iIILsFyCZQpuQF y6TI4qtkYbO2ta8R04S6VgQwAUqQLoUJSZJgyyhG49mbsoROCMvhnSCnI8PBlkkh COxJG+ltPXI/iqN7U9SpFwL3rnSSTxtjZY3T4gITHu3IPysz5/YiraD+L3zB9x4l VBHYmrBjxywQEjhHDAKeDGYfQWtK5QMP0+TE7tclmsYWac/4UkE8YvDJ9EDsFKQh enlx/7eNDaOwvFsQkD6Ujg8ZQ0SHTlmvxFFli2AZn7aJ8VaQQ7X1sLyLraXL19Q= =s5gI -----END PGP SIGNATURE-----