[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Accepted chromium 135.0.7049.52-1 (source) into unstable



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Wed, 02 Apr 2025 02:04:23 -0400
Source: chromium
Architecture: source
Version: 135.0.7049.52-1
Distribution: unstable
Urgency: high
Maintainer: Debian Chromium Team <chromium@packages.debian.org>
Changed-By: Andres Salomon <dilinger@debian.org>
Changes:
 chromium (135.0.7049.52-1) unstable; urgency=high
 .
   [ Andres Salomon ]
   * New upstream stable release.
     - CVE-2025-3066: Use after free in Navigations.
       Reported by Sven Dysthe (@svn-dys).
     - CVE-2025-3067: Inappropriate implementation in Custom Tabs.
       Reported by Philipp Beer (TU Wien).
     - CVE-2025-3068: Inappropriate implementation in Intents.
       Reported by Simon Rawet.
     - CVE-2025-3069: Inappropriate implementation in Extensions.
       Reported by NDevTK.
     - CVE-2025-3070: Insufficient validation of untrusted input in
       Extensions.
     - CVE-2025-3071: Inappropriate implementation in Navigations.
       Reported by David Erceg.
     - CVE-2025-3072: Inappropriate implementation in Custom Tabs.
       Reported by Om Apip.
     - CVE-2025-3073: Inappropriate implementation in Autofill.
       Reported by Hafiizh.
     - CVE-2025-3074: Inappropriate implementation in Downloads.
       Reported by Farras Givari.
   * d/patches:
     - upstream/optional.patch: drop, merged upstream.
     - upstream/qualifications.patch: drop, merged upstream.
     - fixes/lens-optional.patch: drop, merged upstream.
     - fixes/optional.patch: drop, merged upstream.
     - fixes/swiftshader-llvm.patch: drop, merged upstream.
     - fixes/variant.patch: drop, merged upstream.
     - bookworm/clang19.patch: refresh.
     - bookworm/gn-revert-path-exists.patch: add build fix to work around
       older gn.
     - ungoogled/disable-privacy-sandbox.patch: refresh from ungoogled.
     - fixes/make-pair.patch: add a gcc-specific build fix.
     - disable/buildtools-libc.patch: add patch to remove libc build stuff.
 .
   [ Timothy Pearson ]
   * Enable pointer compression on ppc64le
     This fixes V8 OOM conditions noted on e.g. https://trac.ffmpeg.org
   * d/patches/ppc64le:
     - v8/0001-Enable-ppc64-pointer-compression.patch
     - sandbox/0001-sandbox-linux-Update-syscall-helpers-lists-for-ppc64.patch:
       refresh for upstream changes
 .
   [ Daniel Richard G. ]
   * d/rules: Add switch to allow downloading either Google's upstream tarball,
     or an independently-created one from Gentoo. Default to the latter.
Checksums-Sha1:
 304d2be285c9bd48791733245ad746a7b59922d8 3830 chromium_135.0.7049.52-1.dsc
 ffd88347c5f9786bef29a41bfa28bef7e13102b0 915606044 chromium_135.0.7049.52.orig.tar.xz
 2aba9f8668e7bdd80e0762aa446b60aa5440f430 337116 chromium_135.0.7049.52-1.debian.tar.xz
 62446eefc1680d83a0826a0038ed5d51ecff9950 27318 chromium_135.0.7049.52-1_source.buildinfo
Checksums-Sha256:
 d387f446d4d22cee0afcd79fadeb950f72e5c77125e9629330a59405cdb2d36f 3830 chromium_135.0.7049.52-1.dsc
 fe028f5b6aed8c8df13d34c632ab4cf2c9aa2e783a8c34161ebe51db38f00ae4 915606044 chromium_135.0.7049.52.orig.tar.xz
 ebea127b9aae44d324014b39eb0afde2532d7242735e179a8d0f70fa703b55f7 337116 chromium_135.0.7049.52-1.debian.tar.xz
 37236f8dbbcb3576511f6c0460ee02c5206ae2b520ca08473b0299f436f9f8e1 27318 chromium_135.0.7049.52-1_source.buildinfo
Files:
 3c4f1f82b0e4c84457bd1654eb850d7e 3830 web optional chromium_135.0.7049.52-1.dsc
 1cc83b4c0005615f9ac63648fe40853b 915606044 web optional chromium_135.0.7049.52.orig.tar.xz
 23195355cdd7018f851ac1586205bae0 337116 web optional chromium_135.0.7049.52-1.debian.tar.xz
 29c17a1694574747f3a0855156e59836 27318 web optional chromium_135.0.7049.52-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmftadcUHGRpbGluZ2Vy
QGRlYmlhbi5vcmcACgkQZF0CR8NudjenUg/+JIo9PWR4/gIOrcsx7MmYGQwW1coj
1+k5i9Y8ncFqYxxQyVM3Xy3B2VWeMveNnpT4gXmLKRxzD0Pjl2b+eYcTzsJswxyD
e1srrg7kpwYtNt/k1eMP6yx2HGg0VxVLZ1XtsGeEQEotxrB1sNSJJ8XGMw/qDWch
pXf/025jkoxHC/b/aVnIQDXxgU7hjxR1Di+45sl5KUWi2mYNhKogpPmJ4VkvWdqG
gSTrtOqOM56JWHqbng9QtdAVxJ8PNVULGnBMhgEYeMwxKkDadVj8HT8EoSU9bhXc
Yd/VnOPhVJ4USc1pNEF6Jr1PuKos5mPKiTax6Fu7iTu5ImvOwNpkrVTEt6Mm3fiL
TT/BakgV43UzzBveK9mhycgRNJ+eCSrfRYolihvAq7Ck8WpK6DjeQgS6unevYcG7
urjDr57ottvmnalcyXH7TafgmhUNd9VOS0+N0+zaeccixRHjZB0uow3KHJLnbwYS
VmQB5mdRFRESYFwd6pp+DBEAyh9cofcKvRGCYEnUgW2maNWqAvkzzS96TrCL4F1U
yMQb38d/zB3rHzvQUf0f7GywwC3N26cWkO5s6S52+PiAN62bMk1rHb8fcxrGVOUe
ietyeVPezwVkzjie+T3JJB8yhcTgMkE99CKQGFe9rtpZKOtIvwWQWVxckDyv8OYI
pQ7V9rAD2MXkS4o=
=4pGX
-----END PGP SIGNATURE-----

Attachment: pgp1UG2LHUDRy.pgp
Description: PGP signature


Reply to: