[ubuntu/maverick] chromium-browser 5.0.375.127~r55887-0ubuntu1 (Accepted)
Fabien Tassin
fta at ubuntu.com
Mon Aug 23 17:20:36 BST 2010
chromium-browser (5.0.375.127~r55887-0ubuntu1) maverick; urgency=low
* New upstream release from the Stable Channel (LP: #622823)
This release fixes the following security issues:
- [45400] Critical, Memory corruption with file dialog. Credit to Sergey
Glazunov.
- [49596] High, Memory corruption with SVGs. Credit to wushi of team509.
- [49628] High, Bad cast with text editing. Credit to wushi of team509.
- [49964] High, Possible address bar spoofing with history bug. Credit to
Mike Taylor.
- [50515] [51835] High, Memory corruption in MIME type handling. Credit to
Sergey Glazunov.
- [50553] Critical, Crash on shutdown due to notifications bug. Credit to
Sergey Glazunov.
- [51146] Medium, Stop omnibox autosuggest if the user might be about to
type a password. Credit to Robert Hansen.
- [51654] High, Memory corruption with Ruby support. Credit to kuzzcc.
- [51670] High, Memory corruption with Geolocation support. Credit to
kuzzcc.
* Add the xul libdir to LD_LIBRARY_PATH in the wrapper to help icedtea6-plugin
(LP: #529242). This is needed at least for openjdk-6 6b18.
- update debian/chromium-browser.sh
* No longer use tar --lzma in get-orig-source now that it silently uses xz
(since tar 1.23-2) which is not available in the backports. Use "tar | lzma"
instead so the embedded tarball is always a lzma file
- update debian/rules
* Tweak the user agent to include Chromium and the Distro's name and version.
- add debian/patches/chromium_useragent.patch.in
- update debian/patches/series
- update debian/rules
* Fix a typo in the subst_files rule
- update debian/rules
* Fix a gyp file that triggers an error with newer gyp (because of dead code)
- add debian/patches/drop_unused_rules_to_please_newer_gyp.patch
- update debian/patches/series
* Bump gyp Build-Depends to >= 0.1~svn810 to match upstream requirement
- update debian/control
Date: Fri, 20 Aug 2010 14:09:16 +0200
Changed-By: Fabien Tassin <fta at ubuntu.com>
https://launchpad.net/ubuntu/maverick/+source/chromium-browser/5.0.375.127~r55887-0ubuntu1
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Fri, 20 Aug 2010 14:09:16 +0200
Source: chromium-browser
Binary: chromium-browser chromium-browser-dbg chromium-browser-l10n chromium-browser-inspector
Architecture: source
Version: 5.0.375.127~r55887-0ubuntu1
Distribution: maverick
Urgency: low
Maintainer: Fabien Tassin <fta at ubuntu.com>
Changed-By: Fabien Tassin <fta at ubuntu.com>
Description:
chromium-browser - Chromium browser
chromium-browser-dbg - chromium-browser debug symbols
chromium-browser-inspector - page inspector for the chromium-browser
chromium-browser-l10n - chromium-browser language packages
Launchpad-Bugs-Fixed: 529242 622823
Changes:
chromium-browser (5.0.375.127~r55887-0ubuntu1) maverick; urgency=low
.
* New upstream release from the Stable Channel (LP: #622823)
This release fixes the following security issues:
- [45400] Critical, Memory corruption with file dialog. Credit to Sergey
Glazunov.
- [49596] High, Memory corruption with SVGs. Credit to wushi of team509.
- [49628] High, Bad cast with text editing. Credit to wushi of team509.
- [49964] High, Possible address bar spoofing with history bug. Credit to
Mike Taylor.
- [50515] [51835] High, Memory corruption in MIME type handling. Credit to
Sergey Glazunov.
- [50553] Critical, Crash on shutdown due to notifications bug. Credit to
Sergey Glazunov.
- [51146] Medium, Stop omnibox autosuggest if the user might be about to
type a password. Credit to Robert Hansen.
- [51654] High, Memory corruption with Ruby support. Credit to kuzzcc.
- [51670] High, Memory corruption with Geolocation support. Credit to
kuzzcc.
* Add the xul libdir to LD_LIBRARY_PATH in the wrapper to help icedtea6-plugin
(LP: #529242). This is needed at least for openjdk-6 6b18.
- update debian/chromium-browser.sh
* No longer use tar --lzma in get-orig-source now that it silently uses xz
(since tar 1.23-2) which is not available in the backports. Use "tar | lzma"
instead so the embedded tarball is always a lzma file
- update debian/rules
* Tweak the user agent to include Chromium and the Distro's name and version.
- add debian/patches/chromium_useragent.patch.in
- update debian/patches/series
- update debian/rules
* Fix a typo in the subst_files rule
- update debian/rules
* Fix a gyp file that triggers an error with newer gyp (because of dead code)
- add debian/patches/drop_unused_rules_to_please_newer_gyp.patch
- update debian/patches/series
* Bump gyp Build-Depends to >= 0.1~svn810 to match upstream requirement
- update debian/control
Checksums-Sha1:
ba52360071a3b2f3dc021dc60763cf1128ea2347 1872 chromium-browser_5.0.375.127~r55887-0ubuntu1.dsc
8ec965bc73c4a0193644840a55ca5a2dcdb4c944 96715096 chromium-browser_5.0.375.127~r55887.orig.tar.gz
35c8a81eb67a047458180ddb78772a450c20606b 199124 chromium-browser_5.0.375.127~r55887-0ubuntu1.diff.gz
Checksums-Sha256:
17bd3de4de97c8c9b9c204554fff279e91d082aca12480b7a1e2f830526ce165 1872 chromium-browser_5.0.375.127~r55887-0ubuntu1.dsc
8d277fc31d21babd10308021fb053833f6e04868bc3c200eda360e63f4952453 96715096 chromium-browser_5.0.375.127~r55887.orig.tar.gz
6cb1694ba501a0431b6d7f5502d62c34f7d7dd51cd1fcf55fa0aadd73275b06f 199124 chromium-browser_5.0.375.127~r55887-0ubuntu1.diff.gz
Files:
84a4307e234280d9804c9bbd88353495 1872 web optional chromium-browser_5.0.375.127~r55887-0ubuntu1.dsc
444576d3517850e68b6b51ad19c1cb50 96715096 web optional chromium-browser_5.0.375.127~r55887.orig.tar.gz
eef93786befca96524767f4768dd5bb2 199124 web optional chromium-browser_5.0.375.127~r55887-0ubuntu1.diff.gz
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iEYEARECAAYFAkxynscACgkQaOfNHbbuIOhteACgjwuWdACUU7AptEyFXCvKNx5z
4YYAnjbnRvNszxVAqRonxc2Tt6qnWSnt
=4Fa/
-----END PGP SIGNATURE-----
More information about the Maverick-changes
mailing list