[ubuntu/bionic-updates] chromium-browser 107.0.5304.87-0ubuntu11.18.04.1 (Accepted)

Ubuntu Archive Robot ubuntu-archive-robot at lists.canonical.com
Thu Nov 10 23:36:40 UTC 2022


chromium-browser (107.0.5304.87-0ubuntu11.18.04.1) UNRELEASED; urgency=medium

  * constexpr-doesnt-produce-constant-expression.patch: added

chromium-browser (107.0.5304.87-0ubuntu6.18.04.1) UNRELEASED; urgency=medium

  * Disable Qt, as it creates build issues. This encompasses:
    - Dropping debian/patches/old-qt.patch.
    - Removing Qt from debian/control.

chromium-browser (107.0.5304.87-0ubuntu4.18.04.1) UNRELEASED; urgency=medium

  * Upstream release: 107.0.5304.87
    - CVE-2022-3723: Type Confusion in V8.
    - CVE-2022-3653: Heap buffer overflow in Vulkan.
    - CVE-2022-3654: Use after free in Layout.
    - CVE-2022-3655: Heap buffer overflow in Media Galleries.
    - CVE-2022-3656: Insufficient data validation in File System.
    - CVE-2022-3657: Use after free in Extensions.
    - CVE-2022-3658: Use after free in Feedback service on Chrome OS.
    - CVE-2022-3659: Use after free in Accessibility.
    - CVE-2022-3660: Inappropriate implementation in Full screen mode.
    - CVE-2022-3661: Insufficient data validation in Extensions.
    - CVE-2022-3445: Use after free in Skia.
    - CVE-2022-3446: Heap buffer overflow in WebSQL.
    - CVE-2022-3447: Inappropriate implementation in Custom Tabs.
    - CVE-2022-3448: Use after free in Permissions API.
    - CVE-2022-3449: Use after free in Safe Browsing.
    - CVE-2022-3450: Use after free in Peer Connection.
    - CVE-2022-3201: Insufficient validation of untrusted input in DevTools.
    - CVE-2022-3306: Use-after-free in Ash. 
    - CVE-2022-3305: Use-after-free in Ash. 
    - CVE-2022-3309: Use-after-free in ChromOS.
    - CVE-2022-3314: Use-after-free in ChromeOS. 
    - CVE-2022-3312: Security: Locked devices.
    - CVE-2022-3318: Use-after-free in ChromeOS.
    - CVE-TBD: Use-after-free in OverlayManager. 
    - CVE-TBD: Use-after-free in Ash.
    - CVE-TBD Security: Use-after-free in ARC 
  * debian/control: depend on Qt
  * debian/patches/old-qt.patch: added
  * debian/patches/undefined-mulodi4.patch: added
  * debian/patches/allow-building-on-x86.patch: refreshed
  * debian/patches/build-libc++-with-old-clang.patch: added
  * debian/patches/build-with-old-libva-no-av1.patch: refreshed
  * debian/patches/gn-no-last-commit-position.patch: refreshed
  * debian/patches/linker-oom-armhf.patch: added
  * debian/patches/search-credit.patch: refreshed
  * debian/patches/series: refreshed
  * debian/patches/set-rpath-on-chromium-executables.patch: added
  * debian/patches/suppress-newer-clang-warning-flags.patch: refreshed

chromium-browser (106.0.5249.91-0ubuntu2.18.04.1) UNRELEASED; urgency=medium

  * Upstream release: 106.0.5249.91
    - CVE-2022-3370: Use after free in Custom Elements.
    - CVE-2022-3373: Out of bounds write in V8.
  * debian/patches/build-with-old-libva-no-av1.patch: refreshed
  * debian/patches/suppress-newer-clang-warning-flags.patch: refreshed
  * debian/patches/build-no-invalid-constexpr-error.patch: refreshed
  * debian/patches/fix-init-priority-max.patch: added

Date: 2022-11-03 10:19:09.213289+00:00
Changed-By: Nathan Pratta Teodosio <nathan.teodosio at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/chromium-browser/107.0.5304.87-0ubuntu11.18.04.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Bionic-changes mailing list