Publishing details

Changelog

chromium-browser (1:112.0.5615.165-0ubuntu0.16.04.1sav0) xenial; urgency=medium

  * Upstream release: 112.0.5615.165
    - CVE-2023-1810: Heap buffer overflow in Visuals
    - CVE-2023-1811: Use after free in Frames
    - CVE-2023-1812: Out of bounds memory access in DOM Bindings
    - CVE-2023-1813: Inappropriate implementation in Extensions
    - CVE-2023-1814: Insufficient validation of untrusted input in Safe Browsing
    - CVE-2023-1815: Use after free in Networking APIs
    - CVE-2023-1816: Incorrect security UI in Picture In Picture
    - CVE-2023-1817: Insufficient policy enforcement in Intents
    - CVE-2023-1818: Use after free in Vulkan
    - CVE-2023-1819: Out of bounds read in Accessibility
    - CVE-2023-1820: Heap buffer overflow in Browser History
    - CVE-2023-1821: Inappropriate implementation in WebShare
    - CVE-2023-1822: Incorrect security UI in Navigation
    - CVE-2023-1823: Inappropriate implementation in FedCM
    - CVE-2023-2033: Type Confusion in V8
    - CVE-2023-2133: Out of bounds memory access in Service Worker API
    - CVE-2023-2134: Out of bounds memory access in Service Worker API
    - CVE-2023-2135: Use after free in DevTools
    - CVE-2023-2136: Integer overflow in Skia
    - CVE-2023-2137: Heap buffer overflow in sqlite
  * Build with LLVM 15.0.6 (ppa:savoury1/llvm-defaults-15):
    - debian/control: Bump to {clang,llvm} (>= 1:15.0~) BDs
    - debian/rules: Bump to {clang,clang++,llvm-ar}-15 for gn build
  * Merge these changes from Ubuntu 112.0.5615.49-0ubuntu0.18.04.1 package:
    - d/p/c-std-17.patch: heavily extended
    - d/p/invalid-operands-to-dcheck.patch: added
    - d/p/node-for-arm-too.patch: added
    - d/p/revert-outliner-disable.patch: added
    - d/p/add-missing-cstddef-include.patch: refreshed
    - d/p/search-credit.patch: refreshed

 -- Rob Savoury <email address hidden>  Mon, 24 Apr 2023 10:43:41 -0700

Available diffs

Builds

Built packages

Package files