chromium-browser 15.0.874.106~r107270-0ubuntu0.11.10.1 source package in Ubuntu

Changelog

chromium-browser (15.0.874.106~r107270-0ubuntu0.11.10.1) oneiric-security; urgency=low

  * New upstream release from the Stable Channel (LP: #881786)
    - fix LP: #881607 - Error initializing NSS without a persistent database
    This release fixes the following security issues:
    - [86758] High CVE-2011-2845: URL bar spoof in history handling. Credit to
      Jordi Chancel.
    - [88949] Medium CVE-2011-3875: URL bar spoof with drag+drop of URLs. Credit
      to Jordi Chancel.
    - [90217] Low CVE-2011-3876: Avoid stripping whitespace at the end of
      download filenames. Credit to Marc Novak.
    - [91218] Low CVE-2011-3877: XSS in appcache internals page. Credit to
      Google Chrome Security Team (Tom Sepez) plus independent discovery by
      Juho Nurminen.
    - [94487] Medium CVE-2011-3878: Race condition in worker process
      initialization. Credit to miaubiz.
    - [95374] Low CVE-2011-3879: Avoid redirect to chrome scheme URIs. Credit to
      Masato Kinugawa.
    - [95992] Low CVE-2011-3880: Don’t permit as a HTTP header delimiter. Credit
      to Vladimir Vorontsov, ONsec company.
    - [96047] [96885] [98053] [99512] [99750] High CVE-2011-3881: Cross-origin
      policy violations. Credit to Sergey Glazunov.
    - [96292] High CVE-2011-3882: Use-after-free in media buffer handling.
      Credit to Google Chrome Security Team (Inferno).
    - [96902] High CVE-2011-3883: Use-after-free in counter handling. Credit to
      miaubiz.
    - [97148] High CVE-2011-3884: Timing issues in DOM traversal. Credit to
      Brian Ryner of the Chromium development community.
    - [97599] [98064] [98556] [99294] [99880] [100059] High CVE-2011-3885: Stale
      style bugs leading to use-after-free. Credit to miaubiz.
    - [98773] [99167] High CVE-2011-3886: Out of bounds writes in v8. Credit to
      Christian Holler.
    - [98407] Medium CVE-2011-3887: Cookie theft with javascript URIs. Credit to
      Sergey Glazunov.
    - [99138] High CVE-2011-3888: Use-after-free with plug-in and editing.
      Credit to miaubiz.
    - [99211] High CVE-2011-3889: Heap overflow in Web Audio. Credit to miaubiz.
    - [99553] High CVE-2011-3890: Use-after-free in video source handling.
      Credit to Ami Fischman of the Chromium development community.
    - [100332] High CVE-2011-3891: Exposure of internal v8 functions. Credit to
      Steven Keuchel of the Chromium development community plus independent
      discovery by Daniel Divricean.

  [ Chris Coulson <email address hidden> ]
  * Refresh patches
    - update debian/patches/dlopen_sonamed_gl.patch
    - update debian/patches/webkit_rev_parser.patch
  * Dropped patches, fixed upstream
    - remove debian/patches/cups_1.5_build_fix.patch
    - update debian/patches/series

  [ Fabien Tassin ]
  * Disable NaCl until we figure out what to do with the private toolchain
    - update debian/rules
  * Do not install the pseudo_locales files in the debs
    - update debian/rules
  * Add python-simplejson to Build-depends. This is needed by NaCl even with
    NaCl disabled, so this is a temporary workaround to unbreak the build, it
    must be fixed upstream
    - update debian/control

  [ Micah Gersten <email address hidden> ]
  * Switch to internal libvpx; This makes updating easier
    - update debian/rules
  * Drop build dependency on libvpx due to the switch to internal libvpx
    - update debian/control
 -- Micah Gersten <email address hidden>   Thu, 27 Oct 2011 02:45:31 -0500

Upload details

Uploaded by:
Micah Gersten on 2011-10-27
Uploaded to:
Oneiric
Original maintainer:
Fabien Tassin
Component:
main
Architectures:
any
Section:
web
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size MD5 Checksum
chromium-browser_15.0.874.106~r107270.orig.tar.gz 204.0 MiB 9324c0423e392d0933ee233e78cee3dd
chromium-browser_15.0.874.106~r107270-0ubuntu0.11.10.1.diff.gz 202.4 KiB 4cb3b9fce8954233b3b245ab74b14775
chromium-browser_15.0.874.106~r107270-0ubuntu0.11.10.1.dsc 2.1 KiB 4000230951e5602358a7ab9997941591

View changes file

Binary packages built by this source

chromium-browser: No summary available for chromium-browser in ubuntu oneiric.

No description available for chromium-browser in ubuntu oneiric.

chromium-browser-dbg: No summary available for chromium-browser-dbg in ubuntu oneiric.

No description available for chromium-browser-dbg in ubuntu oneiric.

chromium-browser-l10n: No summary available for chromium-browser-l10n in ubuntu oneiric.

No description available for chromium-browser-l10n in ubuntu oneiric.

chromium-codecs-ffmpeg: No summary available for chromium-codecs-ffmpeg in ubuntu oneiric.

No description available for chromium-codecs-ffmpeg in ubuntu oneiric.

chromium-codecs-ffmpeg-dbg: No summary available for chromium-codecs-ffmpeg-dbg in ubuntu oneiric.

No description available for chromium-codecs-ffmpeg-dbg in ubuntu oneiric.

chromium-codecs-ffmpeg-extra: No summary available for chromium-codecs-ffmpeg-extra in ubuntu oneiric.

No description available for chromium-codecs-ffmpeg-extra in ubuntu oneiric.

chromium-codecs-ffmpeg-extra-dbg: No summary available for chromium-codecs-ffmpeg-extra-dbg in ubuntu oneiric.

No description available for chromium-codecs-ffmpeg-extra-dbg in ubuntu oneiric.