-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 17 Apr 2024 19:39:48 +0100 Source: flatpak Binary: flatpak flatpak-dbgsym flatpak-tests flatpak-tests-dbgsym gir1.2-flatpak-1.0 libflatpak-dev libflatpak0 libflatpak0-dbgsym Architecture: mips64el Version: 1.14.4-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-03) Changed-By: Simon McVittie Description: flatpak - Application deployment framework for desktop apps flatpak-tests - Application deployment framework for desktop apps (tests) gir1.2-flatpak-1.0 - Application deployment framework for desktop apps (introspection) libflatpak-dev - Application deployment framework for desktop apps (development) libflatpak0 - Application deployment framework for desktop apps (library) Changes: flatpak (1.14.4-1+deb12u1) bookworm-security; urgency=high . * d/p/When-starting-non-static-command-using-bwrap-use.patch, d/p/test-run-Add-a-reproducer-for-CVE-2024-32462.patch: Don't allow an executable name to be misinterpreted as a command-line option for bwrap(1). This prevents a sandbox escape where a malicious or compromised app could ask xdg-desktop-portal to generate a .desktop file with access to files outside the sandbox. (CVE-2024-32462) * d/gbp.conf: Use debian/bookworm packaging branch Checksums-Sha1: 9c77b2e980e47f2320fdfb780e0838021497c34a 6669948 flatpak-dbgsym_1.14.4-1+deb12u1_mips64el.deb 0c5072cefd465d4d30fb0c118bbcf06c638d6067 10403024 flatpak-tests-dbgsym_1.14.4-1+deb12u1_mips64el.deb f0b99090857b2a544e23679dcede9178012557ad 908076 flatpak-tests_1.14.4-1+deb12u1_mips64el.deb 8cd22eccd772005ac8a8213e9ba9a157af9ed2a9 14270 flatpak_1.14.4-1+deb12u1_mips64el-buildd.buildinfo 3e33c2dd039e1e7847e39f35ae2d83374582076d 1205812 flatpak_1.14.4-1+deb12u1_mips64el.deb 225860706ee083e0bf6d89114fa9551ec846c2a1 23044 gir1.2-flatpak-1.0_1.14.4-1+deb12u1_mips64el.deb 0b735abbfe8b13357950520379119870431c89d6 66420 libflatpak-dev_1.14.4-1+deb12u1_mips64el.deb a0320a2af3ab3a424ce6fcdd1ff470309535d424 1613048 libflatpak0-dbgsym_1.14.4-1+deb12u1_mips64el.deb 2e1a9ff8f7026ea4d9ec2eee55d339f465b6b7da 294092 libflatpak0_1.14.4-1+deb12u1_mips64el.deb Checksums-Sha256: 58f3fb3910010e9f457525cff0d2cdd74f19159c9b4b7056e2f523d448c12a41 6669948 flatpak-dbgsym_1.14.4-1+deb12u1_mips64el.deb 8c62f44f51191ecacad1edc5aef39c15264edde612688c80ba1ab75988c383ec 10403024 flatpak-tests-dbgsym_1.14.4-1+deb12u1_mips64el.deb 511c8b0b5b62753026605a91e77fbaeed769893f092c5694aedf3d9da8765b39 908076 flatpak-tests_1.14.4-1+deb12u1_mips64el.deb 9df01687b606b1d3d1146e0d45a012d106ac3a2eb70823550c4ab765fd48fc42 14270 flatpak_1.14.4-1+deb12u1_mips64el-buildd.buildinfo 36c056a21a3e7b004249fa048f27368dfa7ff52148f2c3e7b9b7bce0fa96ceac 1205812 flatpak_1.14.4-1+deb12u1_mips64el.deb e0f28b34dcae131be11b7a437c0d25a2c32fdd10e7a5eaa6e78a86d108b89bb1 23044 gir1.2-flatpak-1.0_1.14.4-1+deb12u1_mips64el.deb a6ec4c06260a3401d73089501d6657b55461642c5ffe96fb62c7a4c359b49dc0 66420 libflatpak-dev_1.14.4-1+deb12u1_mips64el.deb 4b4b22d8eb11ee20b45075d710131f2501ca0df33884a5127ba874076f569bf9 1613048 libflatpak0-dbgsym_1.14.4-1+deb12u1_mips64el.deb 3dd29dd93cead13c8c78242a4ff8a56ffe4762a73915ccb36eade609fe1864ab 294092 libflatpak0_1.14.4-1+deb12u1_mips64el.deb Files: e88550acec6848320ead1b9a165587b2 6669948 debug optional flatpak-dbgsym_1.14.4-1+deb12u1_mips64el.deb 5559c129bdf10d477797fcd93d744a09 10403024 debug optional flatpak-tests-dbgsym_1.14.4-1+deb12u1_mips64el.deb 97b855cfd5bf401892e32a0a3fd22187 908076 misc optional flatpak-tests_1.14.4-1+deb12u1_mips64el.deb f6ebfc4584b0aa1e51dc6a5117bd19cf 14270 admin optional flatpak_1.14.4-1+deb12u1_mips64el-buildd.buildinfo 3b9e3db37f928cf3c05f0d5ad490c8a7 1205812 admin optional flatpak_1.14.4-1+deb12u1_mips64el.deb 79fc81e8ff5292ad395c8c7ddbd47209 23044 introspection optional gir1.2-flatpak-1.0_1.14.4-1+deb12u1_mips64el.deb bba63d1f7b59575b08958ab07f7b15e1 66420 libdevel optional libflatpak-dev_1.14.4-1+deb12u1_mips64el.deb b4d501caf2d989725042f156bf39a1c6 1613048 debug optional libflatpak0-dbgsym_1.14.4-1+deb12u1_mips64el.deb 0a8037e143a4b1443e2d8b871b080334 294092 libs optional libflatpak0_1.14.4-1+deb12u1_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEunmvxaaGKuI+hxxClmZGXOM83t8FAmYhdGMACgkQlmZGXOM8 3t9ZcA/+J/eP4Qp9ZMv5AvcTu9AdfCIawWtHRvcQdW+vx60IcToDtFLNDb25zt37 2Ij5zWaQ8msxr1Cfjm70MJ+0NhxsDyQdCd7LEncGbWDlYKpb+H76LeqsL4SfVBj2 Cz30CrGu0W1hExcLuCyNUGfneTMskUChkUBf5lB0ZRr6XvP2n8P9/YOWjyAEjafx kFhci98xuBlXsdd5SM6ZZneEYslT2NPxYY80jZFMV9evA1kAuF7p3eCMkxIsO34u RV0o4rX/7+Fhcp2oeqh1+USnw21nukkKMUpav9A6slM3enwNo7KGQNO0GkYdQj57 Tzz1rAofgJwnHSjSgTPJsnlb/FEnWfjknnTh6AWa2FTtVgcHKvYwMLilxDZ7NSWN s223PeC1Jw2VYloi1KuwpULLvuC1NKTWFwsXIRCr+FeDQ9IZlvBje3AgcN94O5T7 HAYmGsFxBDsUWi3pErMu4TRxP/k/qfSkF63th93itOgfqtwdEpUEMGWhyourRs1Z GxeZCukMGzRwL6HXQXKaUCdsOu9EzgZ164fz/ien9WUX0sOA1HtHuuZDoWaEJudl XbuEZdyGqjIo2dZkBRtHEwvrrnKUDlbnHgfJ+4AVBccKFY8QT1XxOqAQRGk45JUT BSR4zLUmTDPcOLnpu2o+53XvQe/k+eCOv5jiCDcCLhCvQcNaDjA= =Ebyp -----END PGP SIGNATURE-----