-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 17 Apr 2024 19:39:48 +0100 Source: flatpak Binary: flatpak flatpak-dbgsym flatpak-tests flatpak-tests-dbgsym gir1.2-flatpak-1.0 libflatpak-dev libflatpak0 libflatpak0-dbgsym Architecture: mipsel Version: 1.14.4-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Simon McVittie Description: flatpak - Application deployment framework for desktop apps flatpak-tests - Application deployment framework for desktop apps (tests) gir1.2-flatpak-1.0 - Application deployment framework for desktop apps (introspection) libflatpak-dev - Application deployment framework for desktop apps (development) libflatpak0 - Application deployment framework for desktop apps (library) Changes: flatpak (1.14.4-1+deb12u1) bookworm-security; urgency=high . * d/p/When-starting-non-static-command-using-bwrap-use.patch, d/p/test-run-Add-a-reproducer-for-CVE-2024-32462.patch: Don't allow an executable name to be misinterpreted as a command-line option for bwrap(1). This prevents a sandbox escape where a malicious or compromised app could ask xdg-desktop-portal to generate a .desktop file with access to files outside the sandbox. (CVE-2024-32462) * d/gbp.conf: Use debian/bookworm packaging branch Checksums-Sha1: 369192470ae01f78be3b0f5df564e4cc0012f673 6410444 flatpak-dbgsym_1.14.4-1+deb12u1_mipsel.deb ee42146f7ca531f934eadb405c8173cec2e18cd6 9989484 flatpak-tests-dbgsym_1.14.4-1+deb12u1_mipsel.deb a51bf66aa4d5ffad82b255924670dbab061237f3 911044 flatpak-tests_1.14.4-1+deb12u1_mipsel.deb 45d1863c00c52038f62ba8972aaf4552120b7d2a 14208 flatpak_1.14.4-1+deb12u1_mipsel-buildd.buildinfo 358ead0125af09f8aed0f49f9209fd92cec257b7 1216956 flatpak_1.14.4-1+deb12u1_mipsel.deb 7f83cca741bf6c82480cb1db8f7dc079fe2d35b8 23012 gir1.2-flatpak-1.0_1.14.4-1+deb12u1_mipsel.deb 61b1a7f418469c110a9c0fce4edf5400295ba452 66428 libflatpak-dev_1.14.4-1+deb12u1_mipsel.deb 36ebc3e385abb94959f6e4587ebab323fb0ff681 1554392 libflatpak0-dbgsym_1.14.4-1+deb12u1_mipsel.deb 8ad2d598f7ac26ddb0b4b6c8912dfb023ab5a90d 301608 libflatpak0_1.14.4-1+deb12u1_mipsel.deb Checksums-Sha256: 75de45812fbec450d2610c570f0c94e497bdcd915b4e9b820f62fb55babf1459 6410444 flatpak-dbgsym_1.14.4-1+deb12u1_mipsel.deb 7e110ee37353e2f1a5adabb48091db0da42fd004aac38d7348674fb45dce14f6 9989484 flatpak-tests-dbgsym_1.14.4-1+deb12u1_mipsel.deb 65619ed12fb7b9adb9351c3e4a871134ea6d7e87c31435cbdb1332be381a5625 911044 flatpak-tests_1.14.4-1+deb12u1_mipsel.deb 10b66d5f8956e2a1b44c32a751b82c6dd5293428ae9eac2da87cb29f43a73cac 14208 flatpak_1.14.4-1+deb12u1_mipsel-buildd.buildinfo 4b15ecead90f3f6108b4954217f30e56ba9ecf8d1171bf4cb30d7603b68ad6b1 1216956 flatpak_1.14.4-1+deb12u1_mipsel.deb 602034361a21279bfccc22ed6c895596beeab4f51ad938c3d124902b7203faae 23012 gir1.2-flatpak-1.0_1.14.4-1+deb12u1_mipsel.deb 8daca6c88766c25e702f9274e1abacd9736ff9b5087058aa6a6f9d82eb015246 66428 libflatpak-dev_1.14.4-1+deb12u1_mipsel.deb 9a195ef3b26cbb6842d1e6e669f831c3d00b5f8849e3494dc7ed2ad5d3f8021a 1554392 libflatpak0-dbgsym_1.14.4-1+deb12u1_mipsel.deb 9738ef6c3020d1f421b0c24e98b77641fea9efcaa557ec2d09adba23169f51a3 301608 libflatpak0_1.14.4-1+deb12u1_mipsel.deb Files: 6de7134c54cf33f034976aa7b983c6c5 6410444 debug optional flatpak-dbgsym_1.14.4-1+deb12u1_mipsel.deb f10d1733f23282fa3bb96bc2a719e1b7 9989484 debug optional flatpak-tests-dbgsym_1.14.4-1+deb12u1_mipsel.deb 8503c246cd962747708620fe152fffa8 911044 misc optional flatpak-tests_1.14.4-1+deb12u1_mipsel.deb c86013336eea7b207f7e56f108b3072e 14208 admin optional flatpak_1.14.4-1+deb12u1_mipsel-buildd.buildinfo 749ce1787c3156f72d935bd87c933442 1216956 admin optional flatpak_1.14.4-1+deb12u1_mipsel.deb 81fb3e185d10946623616b5e4c30a9ad 23012 introspection optional gir1.2-flatpak-1.0_1.14.4-1+deb12u1_mipsel.deb 7c7f04f54acd44ce861af1a020eee5ec 66428 libdevel optional libflatpak-dev_1.14.4-1+deb12u1_mipsel.deb 8f9d1da782aadae938eafcbd6d66c46f 1554392 debug optional libflatpak0-dbgsym_1.14.4-1+deb12u1_mipsel.deb f425de169ebb55205c8e92c8a292de7d 301608 libs optional libflatpak0_1.14.4-1+deb12u1_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEuQAPGkYIXAAfq7z1C2Vm2FYVKKAFAmYhdCsACgkQC2Vm2FYV KKD5wQ/+JfDNORaqbBkz8SZjynea5B5KzhjQLtL+73V67ye0v5/ZyS0Ueqg6xCou +21UyNltY56MxlR2BThMea/VIRgDlLlrfgzm3lElF3+EZO+j9iLLzZlhPDBJPxJb vvPpPYLLRdskVe/D91hQDthbb6RWvBmNgBaHKCwZPPBRO4i93rtcMnDNKoKDEVXs Ozlh6IVTVRpKcjwkQ7LFuxoJkH7bDVRVMr8peLzALjmnbLK6BbdI1+NEbxhZCl09 z8yBEGHCfpTLiWwifrg/f35rK/b9c2XyjYLfC39auE3TnCXAb5k93OU3/bwDA+01 cO+kb2jPanNKxJLxfUTY7fkmHUybo7SQLwCmwMj2TeO3n+7QfJwnD/EfaGaWVfx3 ygUtV5ST8+6OphrRAUqYbwr/gysf02jE6Q+OrALhJiz9nodTWLF66Bmhx1RGT+et TL1YCV67+b7/nXrB0aU9kzyduw4at9H9GIgeHeR5zbxcVBiNsL+8eLotHvJIOwQv QqrGqA49khI8/geV7Lbx7x8LsbBEOXs1V0GdxUbztBWVKl/YBSWan8/mqIs0GZho Xo97/XImUu6YdXYHXIZKd9llMBGTQos2zvR1SUH6wcJiPb0bqUWLVwOyeGuMeeVW 6FkWEP1dNXlyH9U48nwZabCKOAMaAON1DnbvaTfXHZ/trzxdDRY= =Sren -----END PGP SIGNATURE-----