Changelog
chromium-browser (13.0.782.215~r97094-1) unstable; urgency=low
[ Michael Gilbert ]
* Remove all automatically generated files during clean up (this makes
it possible to build from source twice in a row now).
* Bump standards version to 3.9.2.
* Fix an obsolete character encoding in debian/copyright.
* Fix build failure with cups >= 1.5.0.
* Don't support lenny's cups anymore.
* Use system config.guess and config.sub for yasm's autotools files.
* Add chromium-browser.png symlink so old menu entries keep their icons
(closes: #622841).
* Add chromium-browser manpage symlink.
* Clean up package short descriptions.
[ Giuseppe Iuculano ]
* Move the compatibility symlinks to the chromium-browser package
* Fix the Vcs-Browser control field
* New stable release:
- High CVE-2011-2823: Use-after-free in line box handling. Credit to Google
Chrome Security Team (SkyLined) and independent later discovery
by miaubiz.
- High CVE-2011-2824: Use-after-free with counter nodes. Credit to miaubiz.
- High CVE-2011-2825: Use-after-free with custom fonts. Credit to wushi of
team509 reported through ZDI (ZDI-CAN-1283), plus indepdendent later
discovery by miaubiz.
- High CVE-2011-2821: Double free in libxml XPath handling. Credit to Yang
Dingning from NCNIPC, Graduate University of Chinese Academy of Sciences.
- High CVE-2011-2826: Cross-origin violation with empty origins.
Credit to Sergey Glazunov.
- High CVE-2011-2827: Use-after-free in text searching. Credit to miaubiz.
- High CVE-2011-2828: Out-of-bounds write in v8.
Credit to Google Chrome Security Team (SkyLined).
- High CVE-2011-2829: Integer overflow in uniform arrays.
Credit to Sergey Glazunov.
* Added autotools-dev in Build-Depends
-- Giuseppe Iuculano <email address hidden> Tue, 23 Aug 2011 17:31:19 +0200