chromium 104.0.5112.101-1 source package in Debian

Changelog

chromium (104.0.5112.101-1) unstable; urgency=high

  * New upstream security release.
    - CVE-2022-2852: Use after free in FedCM.
      Reported by Sergei Glazunov of Google Project Zero
    - CVE-2022-2854: Use after free in SwiftShader. Reported by Cassidy
      Kim of Amber Security Lab, OPPO Mobile Telecommunications Corp. Ltd.
    - CVE-2022-2855: Use after free in ANGLE. Reported by Cassidy Kim
      of Amber Security Lab, OPPO Mobile Telecommunications Corp. Ltd.
    - CVE-2022-2857: Use after free in Blink. Reported by Anonymous
    - CVE-2022-2858: Use after free in Sign-In Flow.
      Reported by raven at KunLun lab
    - CVE-2022-2853: Heap buffer overflow in Downloads.
      Reported by Sergei Glazunov of Google Project Zero
    - CVE-2022-2856: Insufficient validation of untrusted input in Intents
      Reported by Ashley Shen and Christian Resell of Google Threat
      Analysis Group
    - CVE-2022-2859: Use after free in Chrome OS Shell. Reported by
      Nan Wang(@eternalsakura13) and Guang Gong of 360 Alpha Lab
    - CVE-2022-2860: Insufficient policy enforcement in Cookies.
      Reported by Axel Chong
    - CVE-2022-2861: Inappropriate implementation in Extensions API.
      Reported by Rong Jian of VRI
  * Change default search engine to DuckDuckGo for privacy reasons.
    Set a different search engine under Settings -> Search Engine
    (closes: #956012).
  * Drop a bunch of versioned build-deps that have been satisfied
    since at least oldoldstable.
  * debian/NEWS.Debian:
    - Document upstream dropping support for older TLSv1 and TLSv1.1
      protocols (closes: #1005808).
    - Document upstream dropping support for older x86 CPUs without
      SSE3 instruction support (closes: #1010407).
    - Document the Google to DuckDuckGo change.
    - Document upstream's config renaming of AuthServerWhitelist to
      AuthServerAllowlist (closes: #1013268).

 -- Andres Salomon <email address hidden>  Tue, 16 Aug 2022 17:29:29 -0400

Upload details

Uploaded by:
Debian Chromium Team
Uploaded to:
Sid
Original maintainer:
Debian Chromium Team
Architectures:
i386 amd64 arm64 armhf all
Section:
misc
Urgency:
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Downloads

File Size SHA-256 Checksum
chromium_104.0.5112.101-1.dsc 3.5 KiB 28f131fb7a26114a7555ad5f11670bc2c636cf378bf402bb98ff725d7ebccd18
chromium_104.0.5112.101.orig.tar.xz 582.7 MiB c56a57a2e3f25ed3b5ad6e0f239171d5f8e534d35631b72ea23f33feb8519067
chromium_104.0.5112.101-1.debian.tar.xz 205.2 KiB f4b7a1bd0fefb3092bb4a2371733c203638e634f8be7d1ecc3240ab32a97b924

No changes file available.

Binary packages built by this source