-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Mon, 11 Dec 2023 13:32:06 +0100 Source: webkit2gtk Architecture: source Version: 2.42.3-1~deb11u1 Distribution: bullseye-security Urgency: medium Maintainer: Debian WebKit Maintainers Changed-By: Alberto Garcia Changes: webkit2gtk (2.42.3-1~deb11u1) bullseye-security; urgency=medium . * Rebuild for bullseye-security. - Fixes CVE-2023-42916 and CVE-2023-42917. * gcc 10 segfaults when building webkit in amd64 (see #1008098) so use clang instead. Keep using gcc in other architectures because clang has problems in at least i386, arm64 and mipsel (see #1010329 and #1016811). - debian/rules: Tell CMake to use clang. - debian/control.in: Build depend on clang. * Build libsoup2 packages only. - debian/rules: Set ENABLE_SOUP3=NO, ENABLE_GTK4=NO and USE_PREBUILT_DOCS=YES. - debian/control.in: Remove build dependency on ccache. * debian/rules: - Disable USE_AVI, USE_GBM, USE_GSTREAMER_TRANSCODER and USE_JPEGXL due to missing or additional build dependencies. * debian/control.in: - Don't require version 1.20.0 of libgstreamer-plugins-bad1.0-dev. - Remove build dependency on libjxl-dev. * debian/patches/disable-dmabuf.patch: - Disable the DMABuf renderer in all cases in bullseye (see #1054101). Checksums-Sha1: 2b0b86a46d008b0ad99dc60c1cc9758bc52db558 3929 webkit2gtk_2.42.3-1~deb11u1.dsc 1f07562f5009543f1d7427e28f2eff30d3ad15c5 32023120 webkit2gtk_2.42.3.orig.tar.xz afac16f62e893a774eb061f3290024443e254b56 195 webkit2gtk_2.42.3.orig.tar.xz.asc 32d2cc3ba5aaefdf0156acc0074b7b9435167065 85512 webkit2gtk_2.42.3-1~deb11u1.debian.tar.xz e0dc50110d9280f54b35f04e71c047ee1b16cebf 15467 webkit2gtk_2.42.3-1~deb11u1_source.buildinfo Checksums-Sha256: 0512c8f9a1db616eb313279aebda4c5e17265c5b1e7bf349fabfe7cc5a149173 3929 webkit2gtk_2.42.3-1~deb11u1.dsc 0a1a4630045628b3a6fe95da72dc47852cff20d66be1ac6fd0d669c88c13d8e2 32023120 webkit2gtk_2.42.3.orig.tar.xz 350b80ec3e4adccdd0d154916f05b5b1bd793af7432d086f57e52eed03ca71d5 195 webkit2gtk_2.42.3.orig.tar.xz.asc 6ef0d0d0df6118ea70fe8b4cdc6b811348d7de2308b8a7efa8628313aaaa7d1e 85512 webkit2gtk_2.42.3-1~deb11u1.debian.tar.xz 74023b566e3f5d7f50e73d7e6a5ea2f5a80e9207d089a9707c848893381336e8 15467 webkit2gtk_2.42.3-1~deb11u1_source.buildinfo Files: 6fec79088aebad234786b9ccd36e3284 3929 web optional webkit2gtk_2.42.3-1~deb11u1.dsc de1b3611ee738a4173abb5e897bc09e3 32023120 web optional webkit2gtk_2.42.3.orig.tar.xz 0dd699049cef704b6ee9fbaf9048695a 195 web optional webkit2gtk_2.42.3.orig.tar.xz.asc fa071086f70e783684668902cec5a00a 85512 web optional webkit2gtk_2.42.3-1~deb11u1.debian.tar.xz bd7f98f4d1070113f59c051cca8d84bd 15467 web optional webkit2gtk_2.42.3-1~deb11u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEYrwugQBKzlHMYFizAAyEYu0C2AIFAmV3A34ACgkQAAyEYu0C 2ALVxA/+PDVmJtf/74QKMjfRdKNOR5jsavK0w1HfMVDUrFI+IvGAwM4tFhyh1Eq/ hdFC7SecE8pWVu/AXAJDz38Imlkn/m0iRlToEy+HEH4ohqxvZVky/sdVKAtpWsM6 kMx8AlwW5ChKX6RcMFn2VlO9c1Mkd1vwVQJuDJWw1s6BIHkMQv37hTI4asyEzTXl uIpTI+uTfLtZDlq2M/FSeDIKDFJRol/yuIh7o6w1LSRgQoksx+UZrV9bTkAIZrWf sgwkt5/uAB5rZ9nSN2Kpver6mqoQNcMSplOc5hHLcLJ1+icAaSnMb5YdVRr1BDkx oTwq2/ZRnsfmZ+XLHecuWmQ8r29UsZjE1sDsBLZrczMuMVuYaNDzZl4AFnpQrgQr QOgLadvGQ5EPp8I+5GfC9gJmSEX/FOF6d4B0hIHlB3pWt6H0yYBXYXLuqZPToNcd V+6b40jGCaBD2c0fm/AmcZM2ab3/w11YaHFwgUtU1NLbm88wHf2XhQedFxJBaOU+ ZnIYZZZqB1ZKUZ3y4JBoi1iYHY6Z5hbGnKFPhr/CEp+IM4fnkZZuagjgIUjwz+mU c1TrprMMt10Bkor8xPbQGLHqGlz+UnlyrvRu6aLDLktSTOcSgD/fzcYlAo64JDEY 8UkwKIe7aI/lJmZ8TjfUggz0ptzmIuEDhTvFUKSQCLDjCAGWnys= =+3Jy -----END PGP SIGNATURE-----