-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 02 Apr 2024 18:28:18 -0400 Source: chromium Architecture: source Version: 123.0.6312.105-1~deb12u1 Distribution: bookworm-security Urgency: high Maintainer: Debian Chromium Team Changed-By: Andres Salomon Changes: chromium (123.0.6312.105-1~deb12u1) bookworm-security; urgency=high . * New upstream security release. - CVE-2024-3156: Inappropriate implementation in V8. Reported by Zhenghang Xiao (@Kipreyyy). - CVE-2024-3158: Use after free in Bookmarks. Reported by undoingfish. - CVE-2024-3159: Out of bounds memory access in V8. Reported by Edouard Bochin (@le_douds) and Tao Yan (@Ga1ois) of Palo Alto Networks, via Pwn2Own 2024. Checksums-Sha1: 6bcddb0884e5c3af9a6abde72bb66895e3a5ca36 3742 chromium_123.0.6312.105-1~deb12u1.dsc 63961370cb244aa2d2e6be788495f9af44d0bf88 836664148 chromium_123.0.6312.105.orig.tar.xz f6138a663cd0c375500254f12c8b2898d596c87a 409576 chromium_123.0.6312.105-1~deb12u1.debian.tar.xz a747ee450e865f2ddcfa9dddcf8bc765100fff1a 21674 chromium_123.0.6312.105-1~deb12u1_source.buildinfo Checksums-Sha256: d5334ba2b09ebeb6e5c26ee46ec14609a816fb535afb55c3a8a36878b4c13cf3 3742 chromium_123.0.6312.105-1~deb12u1.dsc f4328c1991d2a77ad9c6165b574231f474fe048a52ef2f40c3bd2cc9602f19a0 836664148 chromium_123.0.6312.105.orig.tar.xz 3757e327dedb8341132eeafdb5c69a6ed7b6fc5eba82ffd8dd17d47b20c6e591 409576 chromium_123.0.6312.105-1~deb12u1.debian.tar.xz 86e6a679bb9453b701ac4e5efba980efc622b80fe903352dd8ff6aaf28823eb5 21674 chromium_123.0.6312.105-1~deb12u1_source.buildinfo Files: c88e3977285ffc5741302b5f598f5b0a 3742 web optional chromium_123.0.6312.105-1~deb12u1.dsc 7d3a8b1ba3c7beadd284a3178e9e115e 836664148 web optional chromium_123.0.6312.105.orig.tar.xz 9c3d87d856514ecde43a99f394fabebd 409576 web optional chromium_123.0.6312.105-1~deb12u1.debian.tar.xz bfddd1ad44a37d169152d2dd31026e3b 21674 web optional chromium_123.0.6312.105-1~deb12u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJIBAEBCAAyFiEEUAUk+X1YiTIjs19qZF0CR8NudjcFAmYM9gUUHGRpbGluZ2Vy QGRlYmlhbi5vcmcACgkQZF0CR8Nudjd1PQ//SVNf6NYIMzs9khrcwqZ2hG0OvTEd c9P7fpQjFahD7D2Cg+1vzQ+Vmpq7Nc/4+RvpkgJVzJaVL2x3bncYj0UoOF+01mOZ BhEKD7bb8M2h4QNojeq0x7OQ+/V2atLuIPVTvQPKXHqo3pCMxoPGrXlUeZ1le92m IejEfP37EZcHMbotQ7pnp0bdoIWZw+zUvVQBwkfkHH2bFXJo8YUk2dhm5y0r6uK5 b201xeCTu0gFwO+OzfAL5ngp9sXVUfcyq0KgCPFN4v56N4eQyhV9jorrgacUY8+5 gGX4WsQnyeIpQUAOKn7TcwsTtoeXQBhdPfTgd4fHnnN2k21ZOhdB67ZVS6fUdDJn ya8lJh2J5ZijjVXICj0u8bNuzoTT9qJ1h2LopCE56LDEKUWpgIHd5L20RvcWmCv4 y0NYSYTKqHqymZReGlsMui+hb0v84OobjT0wN9sU6Rbb7vzTm9A+6kOcuxbbFND3 LsqeLqgBjwRUSYZoH67L9c9mUqqjiOpQMNQLJKDkBUlxaJU/xLyyhHk49+5GjLMt PLmkJn9X0ZL9XPdSIhkU3q6UyveemnBNfcW8pTTkdle+636C4/UEgFVV5YSzAFS4 yCOnWqDf84nuVKdIxEokd2yyk19a15V4BZ6XlD2iMFSAKTdDQzjCoBMyfXYmzGPY CZ+T6Mf5bqSnSfA= =ye4K -----END PGP SIGNATURE-----