-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 17 Apr 2024 19:43:12 +0100 Source: flatpak Binary: flatpak flatpak-dbgsym flatpak-tests flatpak-tests-dbgsym gir1.2-flatpak-1.0 libflatpak-dev libflatpak0 libflatpak0-dbgsym Architecture: mips64el Version: 1.10.8-0+deb11u2 Distribution: bullseye-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-03) Changed-By: Simon McVittie Description: flatpak - Application deployment framework for desktop apps flatpak-tests - Application deployment framework for desktop apps (tests) gir1.2-flatpak-1.0 - Application deployment framework for desktop apps (introspection) libflatpak-dev - Application deployment framework for desktop apps (development) libflatpak0 - Application deployment framework for desktop apps (library) Changes: flatpak (1.10.8-0+deb11u2) bullseye-security; urgency=high . * d/p/When-starting-non-static-command-using-bwrap-use.patch, d/p/test-run-Add-a-reproducer-for-CVE-2024-32462.patch: Don't allow an executable name to be misinterpreted as a command-line option for bwrap(1). This prevents a sandbox escape where a malicious or compromised app could ask xdg-desktop-portal to generate a .desktop file with access to files outside the sandbox. (CVE-2024-32462) Checksums-Sha1: 40fe0272c1d794406ce8c07799f085582c8252a3 6384060 flatpak-dbgsym_1.10.8-0+deb11u2_mips64el.deb 0229f4357d9606e94a0adb8e701296f75354e29f 7194480 flatpak-tests-dbgsym_1.10.8-0+deb11u2_mips64el.deb 5b332556465b32255fe4f78846f14b5ce561b39d 735520 flatpak-tests_1.10.8-0+deb11u2_mips64el.deb f9d9e5931b318326c7f142e2d5c87c76a73a73bb 14651 flatpak_1.10.8-0+deb11u2_mips64el-buildd.buildinfo 4b769837b6591eea74819747d2dc83327c4f1472 1122912 flatpak_1.10.8-0+deb11u2_mips64el.deb 3e9cb8e798ff261b4f94670b1b30f190ac927de4 37716 gir1.2-flatpak-1.0_1.10.8-0+deb11u2_mips64el.deb b7fe0351ac00d1fb0ce4b8c375c7ac3240a416d4 79548 libflatpak-dev_1.10.8-0+deb11u2_mips64el.deb c7646066e345099745de76441d2e72599e48cc62 1513624 libflatpak0-dbgsym_1.10.8-0+deb11u2_mips64el.deb ac53ceac9737f8dfeef2df92c053d87a07cab314 291624 libflatpak0_1.10.8-0+deb11u2_mips64el.deb Checksums-Sha256: fb8cab17859e43e31162ff0b748c48a8537d00b8e3a8fc87ecc1426669491ba0 6384060 flatpak-dbgsym_1.10.8-0+deb11u2_mips64el.deb eea1ec478dc108c502aa607bd736a96e9a92229206ce6210c4f5416d87b15db8 7194480 flatpak-tests-dbgsym_1.10.8-0+deb11u2_mips64el.deb ea10c0b338a06a9de05f48d3a7e7aabb1f91c84b638485f2657e47e089586b94 735520 flatpak-tests_1.10.8-0+deb11u2_mips64el.deb e65beb8b26ae3a0517bdfe2d797b53a4770385d05c837b0c3d3af4cfaa4ea962 14651 flatpak_1.10.8-0+deb11u2_mips64el-buildd.buildinfo 7afca6683315fca77bd49d05014072fdf0705e4cd558950b97067b21b1448775 1122912 flatpak_1.10.8-0+deb11u2_mips64el.deb a420395c867d423badc3db3d47dbc6bc4f85030e901359f3f69419dbfad352dd 37716 gir1.2-flatpak-1.0_1.10.8-0+deb11u2_mips64el.deb dcbf0bfe35a6c89880989ea5e2ad12c33e6175f5d7b8cd85c46267691ae21060 79548 libflatpak-dev_1.10.8-0+deb11u2_mips64el.deb c238c279fcbe15c73021bd91ea3c7ae151c4fe52626e80ee5c2eb55fccd3bee1 1513624 libflatpak0-dbgsym_1.10.8-0+deb11u2_mips64el.deb 2caf6dd6eb2d49c97fc68c6f59b5b598bde0d5fe49e5b0a8609f0909d3f4e961 291624 libflatpak0_1.10.8-0+deb11u2_mips64el.deb Files: 277aef9dd2f1dde24ae199c7b98a601f 6384060 debug optional flatpak-dbgsym_1.10.8-0+deb11u2_mips64el.deb dd7f8f299ffd1f8b1c96c49d581e5a64 7194480 debug optional flatpak-tests-dbgsym_1.10.8-0+deb11u2_mips64el.deb 16f0cbb9355fa76d870f7e0b27a55b8c 735520 misc optional flatpak-tests_1.10.8-0+deb11u2_mips64el.deb c6d4df8e967a5bbd581902e8a56f8f78 14651 admin optional flatpak_1.10.8-0+deb11u2_mips64el-buildd.buildinfo 3f4e60bf7fee9ed86f9a2b33e398dec0 1122912 admin optional flatpak_1.10.8-0+deb11u2_mips64el.deb 36ab55029feed91be466d0b20f3733d2 37716 introspection optional gir1.2-flatpak-1.0_1.10.8-0+deb11u2_mips64el.deb 9b3232a069a8641d9ec0fb69678245d5 79548 libdevel optional libflatpak-dev_1.10.8-0+deb11u2_mips64el.deb d12b7ff30b8ccb32551654a6d0c00c2e 1513624 debug optional libflatpak0-dbgsym_1.10.8-0+deb11u2_mips64el.deb 9fc7bae7cde139318566bbee936e696f 291624 libs optional libflatpak0_1.10.8-0+deb11u2_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEunmvxaaGKuI+hxxClmZGXOM83t8FAmYhcxUACgkQlmZGXOM8 3t9nahAAjhYS9olD0XREfspqIxyX1FN6BmDCooFN13FQp3NeH8DlGeYY702n01VE jwEnWRyL/6aAFwWG4nWUPpAh2FVV+siUB7v36XNU8c32QDYyYZIls672JzhAlXCJ LLplY1MsBk5VonmlABKZdmF9tXUhReyp9DG62BuwJw8qVzRG2XulqYA7djfKKJDo EDBPbyPWEPNoGCgFvlQeWSkfbeMcx3johLWBQ5ZXnuOE10pWWJwy7rOd0gk+KzoH gUlGcYZgqs+asaQgBJCXbCbrj9V3ysHbl+45lxtHsvkPFxR9+mkiRq+DcfsZNDx4 Zv19RBQsnOwrnBuT4sCdTgkA3CGg9yzyXTT59GVOa746s0xLU7kNliAk2DLlhmrs w7PaS4RdPybfSFponeeqAXjHxqnaAM9dac2QSrJi3SjPaBs6nI+45xiX3g/AT4aU Vl5GOsnGDbFJrV9l3dpbynNWI2kwMZr+RfFKEwtfBb3g0HHyaKiq8chlEokTGYxk T8q3YEfPylOxpHA5SivlfuYTY9tZg88/CqhfncT2R616KVUk+1FQmLKHXKKLRs8k tcvEA9NJmiXCwEFfnBJdd4fgJ/dQhHu5j/egEWvaopA/xlCp0P1BoNfMg9MEJyhH TJ9mi+o7kb8LwjmEFrWRO/6zfrCpkHYNQd3e8Kk037gFOvqyzB0= =pArq -----END PGP SIGNATURE-----