-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 11 Jan 2021 17:04:13 +0100 Source: chromium Binary: chromium chromium-common chromium-common-dbgsym chromium-dbgsym chromium-driver chromium-driver-dbgsym chromium-sandbox chromium-sandbox-dbgsym chromium-shell chromium-shell-dbgsym Architecture: armhf Version: 87.0.4280.141-0.1~deb10u1 Distribution: buster-security Urgency: high Maintainer: armel Build Daemon (henze) Changed-By: Jan Luca Naumann Description: chromium - web browser chromium-common - web browser - common resources used by the chromium packages chromium-driver - web browser - WebDriver support chromium-sandbox - web browser - setuid security sandbox for chromium chromium-shell - web browser - minimal shell Closes: 979135 979520 Changes: chromium (87.0.4280.141-0.1~deb10u1) buster-security; urgency=high . * Non-maintainer upload. * New upstream security release (closes: 979520). - CVE-2021-21106: Use after free in autofill. Reported by Weipeng Jiang @Krace from Codesafe Team of Legendsec at Qi'anxin Group - CVE-2021-21107: Use after free in drag and drop. Reported by Leecraso and Guang Gong of 360 Alpha Lab - CVE-2021-21108: Use after free in media. Reported by Leecraso and Guang Gong of 360 Alpha Lab - CVE-2021-21109: Use after free in payments. Reported by Rong Jian and Guang Gong of 360 Alpha Lab - CVE-2021-21110: Use after free in safe browsing. Reported by Anonymous - CVE-2021-21111: Insufficient policy enforcement in WebUI. Reported by Alesandro Ortiz - CVE-2021-21112: Use after free in Blink. Reported by YoungJoo Lee @ashuu_lee of Raon Whitehat - CVE-2021-21113: Heap buffer overflow in Skia. Reported by tsubmunu - CVE-2020-16043: Insufficient data validation in networking. Reported by Samy Kamkar, Ben Seri at Armis, Gregory Vishnepolsky at Armis - CVE-2021-21114: Use after free in audio. Reported by Man Yue Mo of GitHub Security Lab - CVE-2020-15995: Out of bounds write in V8. Reported by Bohan Liu @P4nda20371774 of Tencent Security Xuanwu Lab - CVE-2021-21115: Use after free in safe browsing. Reported by Leecraso and Guang Gong of 360 Alpha Lab - CVE-2021-21116: Heap buffer overflow in audio. Reported by Alison Huffman, Microsoft Browser Vulnerability Research * Use desktop gl implementation as default. (closes: 979135) Checksums-Sha1: d61d342d14da0f8876deda907fb1198b0a7b0eb6 304648 chromium-common-dbgsym_87.0.4280.141-0.1~deb10u1_armhf.deb 4a231f9c2de5b8596194cf41f360eb810b6ed459 1262252 chromium-common_87.0.4280.141-0.1~deb10u1_armhf.deb 8cd590286f18659f6a14f89638f0efc36433de01 17164904 chromium-dbgsym_87.0.4280.141-0.1~deb10u1_armhf.deb 69fb18acffb59b7eac157c3d61b9ac8a30fb329d 3230160 chromium-driver-dbgsym_87.0.4280.141-0.1~deb10u1_armhf.deb abde71378425bdb260a1aefdd571283b3551ca03 4071616 chromium-driver_87.0.4280.141-0.1~deb10u1_armhf.deb 54cb78ef527c913a36e03bae09c6f7946f1a1d67 11720 chromium-sandbox-dbgsym_87.0.4280.141-0.1~deb10u1_armhf.deb f9587c2c932cab8b4fc1c15f43d259d64c1ee496 109928 chromium-sandbox_87.0.4280.141-0.1~deb10u1_armhf.deb 5c472fa7db1cf718244b2c1c92d71cf709628e36 13616004 chromium-shell-dbgsym_87.0.4280.141-0.1~deb10u1_armhf.deb 4512a19c7bad0668643afb55884234b37b6c8ebc 33839864 chromium-shell_87.0.4280.141-0.1~deb10u1_armhf.deb c2879008f9fd46b660928585668e775a58dfd64c 24859 chromium_87.0.4280.141-0.1~deb10u1_armhf-buildd.buildinfo 5ba30125400b70738f6ed7aff6d207055cb2685a 48877884 chromium_87.0.4280.141-0.1~deb10u1_armhf.deb Checksums-Sha256: 887e95e3e437977ca4ee27df252a88b0df93cd302410f936d1920c8f0d2ab011 304648 chromium-common-dbgsym_87.0.4280.141-0.1~deb10u1_armhf.deb 4829ab69fb4a9d4c2a6eab017448d92cdd88d9024db07f6cd8b1f524e46c0966 1262252 chromium-common_87.0.4280.141-0.1~deb10u1_armhf.deb c5bb52cf5188560afd6464da21457b87621d018e7d06fc3247170b89e73f5785 17164904 chromium-dbgsym_87.0.4280.141-0.1~deb10u1_armhf.deb a6e9bb43a1c8f2b75e99e147e1b2a3420f255ce48f3fc4b420b551947c389a6b 3230160 chromium-driver-dbgsym_87.0.4280.141-0.1~deb10u1_armhf.deb 9e5020a7f4d7fdffc053e03253458fd3f82d5751a432841a92d3fe102665108e 4071616 chromium-driver_87.0.4280.141-0.1~deb10u1_armhf.deb a7c58005875c5ce636c10c8c27795b353c6d41b102a74c30f73b053296a901af 11720 chromium-sandbox-dbgsym_87.0.4280.141-0.1~deb10u1_armhf.deb 2398e10edf6b8c9f96913bad8328e4d5b8189bd09b6acf46fd4cf98439f40571 109928 chromium-sandbox_87.0.4280.141-0.1~deb10u1_armhf.deb f4824473c08450b0e4a5fcff08b9b127f314f1932a87cc4138ce8a0d37be1418 13616004 chromium-shell-dbgsym_87.0.4280.141-0.1~deb10u1_armhf.deb 688de5a499ad06950698a1171b3e24810e1db01d8779fca4430d8f7dedc79f90 33839864 chromium-shell_87.0.4280.141-0.1~deb10u1_armhf.deb 1a40d00635c9ed96d799ec093ade03c02836f73471e0a32b6cda636f95c289da 24859 chromium_87.0.4280.141-0.1~deb10u1_armhf-buildd.buildinfo 7e9f42c4e8a03703e614110d466f1e13a3921c428317bab7c335917060fc9bf9 48877884 chromium_87.0.4280.141-0.1~deb10u1_armhf.deb Files: 6a2ce7d23575e62c7243220d30ed6cb4 304648 debug optional chromium-common-dbgsym_87.0.4280.141-0.1~deb10u1_armhf.deb e2fbd62be8dc116028bdabc949c5028f 1262252 web optional chromium-common_87.0.4280.141-0.1~deb10u1_armhf.deb e4508d1fb33f4b881c0fe86cbb773879 17164904 debug optional chromium-dbgsym_87.0.4280.141-0.1~deb10u1_armhf.deb 5d52ecba5d0d59c5698f05ad91c3e660 3230160 debug optional chromium-driver-dbgsym_87.0.4280.141-0.1~deb10u1_armhf.deb e7feabe10acdd9735241851fa89a2877 4071616 web optional chromium-driver_87.0.4280.141-0.1~deb10u1_armhf.deb 834415df88516525f8fc7616120dad80 11720 debug optional chromium-sandbox-dbgsym_87.0.4280.141-0.1~deb10u1_armhf.deb dd889e4a238fef81d55d44c6db891299 109928 web optional chromium-sandbox_87.0.4280.141-0.1~deb10u1_armhf.deb 2344a986da3de8d1c12f394b508df675 13616004 debug optional chromium-shell-dbgsym_87.0.4280.141-0.1~deb10u1_armhf.deb 73254e0f8934a644855eccdc3e04a5a6 33839864 web optional chromium-shell_87.0.4280.141-0.1~deb10u1_armhf.deb e95df73b1eae4f614a6b96f11471c31a 24859 web optional chromium_87.0.4280.141-0.1~deb10u1_armhf-buildd.buildinfo c5d0ed5b1c26796646ad7b2a6e8f4bbd 48877884 web optional chromium_87.0.4280.141-0.1~deb10u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKAwT/5vje5woIwiZ0XMSYkpNX2oFAmAAaNgACgkQ0XMSYkpN X2ryVw//U7GRwSFUTM76dSuGXT0+gMIWPbjl2E4EUd0SR/OjNaF+87+B2mAjUMFr AzaKUvdrWwjBzlupT4T6O7yTXAXLrfVmq9WtMBQTdGSXlJbI0kEXGWYFQOID5gaj EsmncJHFNZqsmVN28u+VPNH1iHufoezu8SnwhXBSHpZhp3CkvgptuMxosikWumdS vYRJ2YQq+Xb0fgFLHVkDdUl0RXrf1RMDhttkgRYSxWtr+vzhAleqbVyR8BBjFsw5 v9Wzwe0RRIwdVXC+8WSn1B9JdtPf+syhv372uYZdgAmmzxvQY4NVMcDUdLhNiBb0 3XeAUKBVPOR9f8wP4lytYqGvcOpioiHM9Ewvh7aoIUPnqi5esQJ1ahWwTMT1inPE oYjug1S3GKRB+XuFsDtqCELak4IscZZVOpGR7isAxrBAugPhAiVpC6adVab2bbTc qLNWBtTQxcTD+rDDjGeVLPaEAkj+iFLbkjYdcPSgk6kydIChVApLhjfJj0EVZnNg cqYXWG1ORY+/46LMpSK5nx7ldP3kyeMTtfIqbBmRmKbnHf9adGqWwZSx1NakbVK0 Us6Xj3HPRC5o+sz7BgCOyb/SxUz5awEYzlBaZ9mpeVrS0tkiOD7sbCHZsVhShSua Ch8aVopQa76C3N7UmAAZkJHMBgbEX7/jiZj8Rx2CyxxLQL/xyb8= =9EzA -----END PGP SIGNATURE-----