-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 07 Aug 2016 03:16:44 +0000 Source: chromium-browser Binary: chromium chromium-dbg chromium-l10n chromium-inspector chromedriver Architecture: source i386 all Version: 52.0.2743.116-1~deb8u1 Distribution: jessie-security Urgency: medium Maintainer: Debian Chromium Maintainers <pkg-chromium-maint@lists.alioth.debian.org> Changed-By: Michael Gilbert <mgilbert@debian.org> Description: chromedriver - web browser - WebDriver support chromium - web browser chromium-dbg - web browser - debugging symbols chromium-inspector - web browser - page inspection support chromium-l10n - web browser - language packs Changes: chromium-browser (52.0.2743.116-1~deb8u1) jessie-security; urgency=medium . * New upstream security release: - CVE-2016-5141 Address bar spoofing. Credit to Sergey Glazunov - CVE-2016-5142 Use-after-free in Blink. Credit to Sergey Glazunov - CVE-2016-5139 Heap overflow in pdfium. Credit to GiWan Go - CVE-2016-5140 Heap overflow in pdfium. Credit to Ke Liu - CVE-2016-5145 Same origin bypass for images in Blink. Credit to Sergey Glazunov - CVE-2016-5143 Parameter sanitization failure in DevTools. Credit to Gregory Panakkal - CVE-2016-5144 Parameter sanitization failure in DevTools. Credit to Gregory Panakkal - CVE-2016-5146: Various fixes from internal audits, fuzzing and other initiatives. Checksums-Sha1: 61024f4c47727258cbf3b7315bb2d20c9349fe6f 4079 chromium-browser_52.0.2743.116-1~deb8u1.dsc 5aada91ff2eb7ac95f7b284993e5cb58e77c4978 469498044 chromium-browser_52.0.2743.116.orig.tar.xz 1b5051b51efd91a533806d9100a21cfa004f388c 181096 chromium-browser_52.0.2743.116-1~deb8u1.debian.tar.xz 7170adc20d31c4c5f01688fad08f1a65e02a019b 40992664 chromium_52.0.2743.116-1~deb8u1_i386.deb 8200d07c09004d2a8524e7512dfcc0de64a67ba8 7647432 chromium-dbg_52.0.2743.116-1~deb8u1_i386.deb e81bf005b857a5b343e35382908ed972d5db6bb6 3142900 chromium-l10n_52.0.2743.116-1~deb8u1_all.deb a7670fa14c19db95fbf0a94333952e3b7daf1913 1349122 chromium-inspector_52.0.2743.116-1~deb8u1_all.deb 9923d952efb2c343c68a181abbd0093aea3ce360 2637948 chromedriver_52.0.2743.116-1~deb8u1_i386.deb Checksums-Sha256: 39baf0d104b44703009bb7f7f2b1e46acccc28fcb37027ca7d961ca11c006b96 4079 chromium-browser_52.0.2743.116-1~deb8u1.dsc 3f7473536f39d01757d1ec3f637a160a27ac7f8d1424b02c0b8e315450822e8b 469498044 chromium-browser_52.0.2743.116.orig.tar.xz e1a7e809fb73a993d8624631b5e54ed2971082210c3a90be4527cab871095d88 181096 chromium-browser_52.0.2743.116-1~deb8u1.debian.tar.xz 072de6f8525fbe5069a6c693a53912051edf9184f87fb4f16ea50b63ac91f7da 40992664 chromium_52.0.2743.116-1~deb8u1_i386.deb bafa5f3dc87cbf0b76c94469c2f5aedee9f7adabd996e0d7ddf9c9b98ce4c8c9 7647432 chromium-dbg_52.0.2743.116-1~deb8u1_i386.deb e662f844eff560dd33bfa2d862c03fd4b3ab4173cfc216348c177a0e1f2cf66f 3142900 chromium-l10n_52.0.2743.116-1~deb8u1_all.deb bb56f9092d344df643dab0eac82af2995c64a822281df34618d7c677275cf226 1349122 chromium-inspector_52.0.2743.116-1~deb8u1_all.deb 64d1827c40b04d13af74830556ad6edbe215e16e62ef5018abeca680714d18bd 2637948 chromedriver_52.0.2743.116-1~deb8u1_i386.deb Files: 439eacceaaed43cde7c7a7de338233e4 4079 web optional chromium-browser_52.0.2743.116-1~deb8u1.dsc 0556fe123398d4b5d1816f4775c88490 469498044 web optional chromium-browser_52.0.2743.116.orig.tar.xz cdff9b35e15be0b610bc320bbfab591f 181096 web optional chromium-browser_52.0.2743.116-1~deb8u1.debian.tar.xz 99e1ec79ca33e8720369e68b886e0dd9 40992664 web optional chromium_52.0.2743.116-1~deb8u1_i386.deb acaf97c490bb825cc07ad075d6d277b3 7647432 debug extra chromium-dbg_52.0.2743.116-1~deb8u1_i386.deb d0f8ecbce1f0adbd91352fd3ad6deab1 3142900 localization optional chromium-l10n_52.0.2743.116-1~deb8u1_all.deb b5059b66e527fc7ef01d8f812d3dd737 1349122 web optional chromium-inspector_52.0.2743.116-1~deb8u1_all.deb e4dc1b585a5286842d378c03cbc96886 2637948 web optional chromedriver_52.0.2743.116-1~deb8u1_i386.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQQcBAEBCgAGBQJXptMgAAoJELjWss0C1vRzQXsf/19oRKrZXe4X62qSLl1CZNP4 OhA3daKYo2qlJ/pU5WcvdcGNOVaEWOIPS20tAvT01/kaDoPGEzNidpvzLx7ybI+4 Y51XcWRxWsaH6WEuZ14rPS9r5qHvsyj+iqQtK7pRefF3aon7KIoSgLiedHodBKqx UsljIqJP68dyfwI7ecZoyIOUfRedOqzJ1I0dTwQ3XqpfQAVZ/Fln5JmDTzmaIcml JDoeerUKU/5FiJ6sdO7bLvYrw1zdELhl1+WrGhmr1DYXyu4AznSt9jH2+ODDFWTT xxiHj1UXS855QhVUajYlbQ+GGUKuqMlb+KKDK+KumTtRxUyGf5Qv5YR+NqY80m6G fSandwDO7FI5j/tzzyMeLXuVedbqLVVyxHGYkfStXodOeWpvrnuS0nECj5BbiAxa Fi/WR38rTMg0pC0aYJmCNUYmQrPIPlMaQPfuDFJ88ufGdDTNX8v9cBELsz3ADWeB VGI1HWvRM7ycHhGKEbdROinT2dCXqrxhDFuvD9W9QJBU6m1DSOHQxqA0MVZS/Wfw uCJzErMhdjZDMSvMFbmZ/UaeFPPZCaZty6KGHuoh58kIwV9r282GuRNEtXWpySzc Uy+dVAFKuQdPqPssQ2vC10yzUCswipOiPBHCn4uhH+ZMPKMwSXw+UHTWqIIxm5Da EOH0EZsxdV7djC42OidUZQj6el8a66QJDIyhFVHQPJjQA7om5nxclYkqCI+g6Q5G go8LKRIQU1N3elEORklDujqld5rt6imzyQ/fXXyu/YpjCO8df+D9NG/oAD0rG4L+ /DiNuLENU04QBrhGf7TikoB4oPzTMa/M1wht5Q4G5RY0G+c/oezRHPdS4/zB0nqk NOH4U9n5ywJKGNI8a3d9zqmAzFJoEZ+8JKv4e7QJP4TjpPDBoqlvet0bcb+vwkF5 Xef+/EqCBkm20b68PwePFAGACJ/dr1hSwlbucQ2TfXazChMi9uA7++5MLPbc5ZV3 VEycpCFBsNcTxrT+vxvVDckbpjqWpXSlP29V/r5H4lRAP2uGeOHZroPwTdfC1b1z ZAwncsWIhEB5lRKXc0U9Or+xaKfpHJ4doq+BywNnhAKyrhhyQ8TpS6b9EiF6PJja 3/OK04RU9iQ+D43mxpNR7vZ3F/Zl2hUDdkpE3Lw7Qyhf3x5OXppLyns1Dd39peXw knTlVzJNOL1XuxKODzoghrNTO6+iXlHYOXfNRMpSm7b5fAowbu4VwkDwt3xA3Uyn 5jplmL8eqtYqRv/loIo2mGASM2dDRdOP8fLDb71u+TvrxiFkhsi6SrIXQoQwYjLK BwhARBjXP/13SkJhOgyw+domeo0X86OZVGvPFyPuQ4LPLS7Pw2TGDj1bwIlPaDg= =c9iN -----END PGP SIGNATURE-----