chromium 123.0.6312.58-1 source package in Debian

Changelog

chromium (123.0.6312.58-1) unstable; urgency=high

  * New upstream stable release.
    - CVE-2024-2625: Object lifecycle issue in V8.
      Reported by Ganjiang Zhou(@refrain_areu) of ChaMd5-H1 team.
    - CVE-2024-2626: Out of bounds read in Swiftshader.
      Reported by Cassidy Kim(@cassidy6564).
    - CVE-2024-2627: Use after free in Canvas. Reported by Anonymous.
    - CVE-2024-2628: Inappropriate implementation in Downloads.
      Reported by Ath3r1s.
    - CVE-2024-2629: Incorrect security UI in iOS.
      Reported by Muneaki Nishimura (nishimunea).
    - CVE-2024-2630: Inappropriate implementation in iOS.
      Reported by James Lee (@Windowsrcer).
    - CVE-2024-2631: Inappropriate implementation in iOS.
      Reported by Ramit Gangwar.
  * d/patches:
    - upstream/bitset.patch: drop, merged upstream.
    - upstream/bookmarknode.patch: drop, merged upstream.
    - upstream/optional.patch: drop, merged upstream.
    - upstream/uniqptr.patch: drop, merged upstream.
    - fixes/gcc13-headers.patch: drop, merged upstream.
    - fixes/optional.patch: drop, merged upstream.
    - fixes/material-utils.patch: drop part that was merged upstream.
    - disable/catapult.patch: refresh.
    - bookworm/constexpr-equality.patch: include another similar fix.
    - bookworm/nvt.patch: refresh.
    - bookworm/undo-internal-alloc.patch: drop, as this was fixed upstream.
    - ungoogled/disable-privacy-sandbox.patch: update from ungoogled-chromium.
    - disable/angle-perftests.patch: drop, replace with a gn build argument.
    - bookworm/rust-downgrade-osstr-users.patch: add new patch to downgrade
      clap-lex crate, as it's using 1.74 features and we only have 1.70.
    - fixes/strlcpy.patch: add strlcpy declaration (closes: #1066235).
    - fixes/optional2.patch: add another missing <optional> inclusion.
    - fixes/stats-collector.patch: add build fix for wrong header.
    - disable/screen-ai-blob.patch: add patch to not register the
      ScreenAI component. Previously, if you opened a PDF and clicked
      "open in reader mode", it would download a binary blob to
      ~/.config/chromium/screen_ai/, and do OCR stuff (and who knows
      what else) in that opaque blob without warning you. We, uh, don't
      want that. (closes: #1066910).
  * d/rules: add angle_build_tests=false build argument, which allows us to
    drop angle-perftests.patch.

  [ Timothy Pearson ]
  * d/patches:
    - fixes/blink-fonts-shape-result.patch: pull in upstream patch for
      compilation failure in Blink SameSizeAsShapeResult class
  * d/patches/ppc64le:
    - ffmpeg/0001-Add-support-for-ppc64.patch: refresh for upstream changes
    - third_party/0003-third_party-ffmpeg-Add-ppc64-generated-config.patch:
      refresh for upstream changes
    - libaom/0001-Add-pregenerated-config-for-libaom-on-ppc64.patch: refresh
      for upstream changes
    - third_party/0001-Add-PPC64-support-for-boringssl.patch: refresh for
      upstream changes
    - third_party/skia-vsx-instructions.patch: refresh & harden Skia against
      timing attacks.

 -- Andres Salomon <email address hidden>  Fri, 22 Mar 2024 12:45:06 -0400

Upload details

Uploaded by:
Debian Chromium Team
Uploaded to:
Sid
Original maintainer:
Debian Chromium Team
Architectures:
i386 amd64 arm64 armhf ppc64el all
Section:
misc
Urgency:
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Downloads

File Size SHA-256 Checksum
chromium_123.0.6312.58-1.dsc 3.6 KiB 649eedf7edd48730f2936c99fbdeb822ed786705e97db2aaa3e0f53e2da944b3
chromium_123.0.6312.58.orig.tar.xz 797.3 MiB 3212a13a281e31e4f8b20ac69c3ed0c87e912105190a42003fb59e227b4ee8f6
chromium_123.0.6312.58-1.debian.tar.xz 367.9 KiB 58d6f79fb29e4756fcba608c7b100bd1ffe3b88373e6dcedbe8b40ff1c05e653

No changes file available.

Binary packages built by this source