[ubuntu/xenial-proposed] chromium-browser 47.0.2526.73-0ubuntu1.1218 (Accepted)

2015-12-08 Thread Chad MILLER
chromium-browser (47.0.2526.73-0ubuntu1.1218) xenial; urgency=medium

  * Upstream release 47.0.2526.73:
- CVE-2015-6765: Use-after-free in AppCache.
- CVE-2015-6766: Use-after-free in AppCache.
- CVE-2015-6767: Use-after-free in AppCache.
- CVE-2015-6768: Cross-origin bypass in DOM.
- CVE-2015-6769: Cross-origin bypass in core.
- CVE-2015-6770: Cross-origin bypass in DOM.
- CVE-2015-6771: Out of bounds access in v8.
- CVE-2015-6772: Cross-origin bypass in DOM.
- CVE-2015-6764: Out of bounds access in v8.
- CVE-2015-6773: Out of bounds access in Skia.
- CVE-2015-6774: Use-after-free in Extensions.
- CVE-2015-6775: Type confusion in PDFium.
- CVE-2015-6776: Out of bounds access in PDFium.
- CVE-2015-6777: Use-after-free in DOM.
- CVE-2015-6778: Out of bounds access in PDFium.
- CVE-2015-6779: Scheme bypass in PDFium.
- CVE-2015-6780: Use-after-free in Infobars.
- CVE-2015-6781: Integer overflow in Sfntly.
- CVE-2015-6782: Content spoofing in Omnibox.
- CVE-2015-6783: Signature validation issue in Android Crazy Linker.
- CVE-2015-6784: Escaping issue in saved pages.
- CVE-2015-6785: Wildcard matching issue in CSP.
- CVE-2015-6786: Scheme bypass in CSP.
- CVE-2015-6787: Various fixes from internal audits, fuzzing and other
  initiatives.
- Multiple vulnerabilities in V8 fixed at the tip of the 4.7 branch
  (currently 4.7.80.23).
  * Upstream release 46.0.2490.86:
- CVE-2015-1302: Information leak in PDF viewer.
  * Upstream release 46.0.2490.71:
- CVE-2015-6755: Cross-origin bypass in Blink.
- CVE-2015-6756: Use-after-free in PDFium.
- CVE-2015-6757: Use-after-free in ServiceWorker.
- CVE-2015-6758: Bad-cast in PDFium.
- CVE-2015-6759: Information leakage in LocalStorage.
- CVE-2015-6760: Improper error handling in libANGLE.
- CVE-2015-6761: Memory corruption in FFMpeg.
- CVE-2015-6762: CORS bypass via CSS fonts.
- CVE-2015-6763: Various fixes from internal audits, fuzzing and other
  initiatives.
  * debian/patches/gpu-hangs: remove. Not useful.
  * Switch to Clang to compile.
  * debian/rules: Explicitly create remoting resources.
  * debian/patches/cr46-missing-test-files:
  * debian/rules: support screen sharing in Hangouts.
  * debian/patches/xdg-settings-multiexec-desktopfiles.patch: Always prefer
local xdg-settings.
  * debian/chromium-browser.desktop: Don't override WM class matching.

Date: Tue, 01 Dec 2015 15:37:11 -0500
Changed-By: Chad MILLER 
Maintainer: Ubuntu Developers 
Signed-By: Chris Coulson 
https://launchpad.net/ubuntu/+source/chromium-browser/47.0.2526.73-0ubuntu1.1218
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Format: 1.8
Date: Tue, 01 Dec 2015 15:37:11 -0500
Source: chromium-browser
Binary: chromium-browser chromium-browser-dbg chromium-browser-l10n 
chromium-codecs-ffmpeg chromium-codecs-ffmpeg-dbg chromium-codecs-ffmpeg-extra 
chromium-codecs-ffmpeg-extra-dbg chromium-chromedriver chromium-chromedriver-dbg
Architecture: source
Version: 47.0.2526.73-0ubuntu1.1218
Distribution: xenial
Urgency: medium
Maintainer: Ubuntu Developers 
Changed-By: Chad MILLER 
Description:
 chromium-browser - Chromium web browser, open-source version of Chrome
 chromium-browser-dbg - chromium-browser debug symbols
 chromium-browser-l10n - chromium-browser language packages
 chromium-chromedriver - WebDriver driver for the Chromium Browser
 chromium-chromedriver-dbg - chromium-chromedriver debug symbols
 chromium-codecs-ffmpeg - Free ffmpeg codecs for the Chromium Browser
 chromium-codecs-ffmpeg-dbg - chromium-codecs-ffmpeg debug symbols
 chromium-codecs-ffmpeg-extra - Extra ffmpeg codecs for the Chromium Browser
 chromium-codecs-ffmpeg-extra-dbg - chromium-codecs-ffmpeg-extra debug symbols
Changes:
 chromium-browser (47.0.2526.73-0ubuntu1.1218) xenial; urgency=medium
 .
   * Upstream release 47.0.2526.73:
 - CVE-2015-6765: Use-after-free in AppCache.
 - CVE-2015-6766: Use-after-free in AppCache.
 - CVE-2015-6767: Use-after-free in AppCache.
 - CVE-2015-6768: Cross-origin bypass in DOM.
 - CVE-2015-6769: Cross-origin bypass in core.
 - CVE-2015-6770: Cross-origin bypass in DOM.
 - CVE-2015-6771: Out of bounds access in v8.
 - CVE-2015-6772: Cross-origin bypass in DOM.
 - CVE-2015-6764: Out of bounds access in v8.
 - CVE-2015-6773: Out of bounds access in Skia.
 - CVE-2015-6774: Use-after-free in Extensions.
 - CVE-2015-6775: Type confusion in PDFium.
 - CVE-2015-6776: Out of bounds access in PDFium.
 - CVE-2015-6777: Use-after-free in DOM.
 - CVE-2015-6778: Out of bounds access in PDFium.
 - CVE-2015-6779: Scheme bypass in PDFium.
 - CVE-2015-6780: Use-after-free in Infobars.
 - CVE-2015-6781: Integer overflow in Sfntly.
 - CVE-2015-6782: Content spoofing in Omnibox.
 - CVE-2015-6783: Signature validation issue in Android Crazy Linker.
 - CVE-2015-6784: Escaping 

[ubuntu/xenial-proposed] chromium-browser 48.0.2564.116-0ubuntu1.1229 (Accepted)

2016-02-23 Thread Chad MILLER
chromium-browser (48.0.2564.116-0ubuntu1.1229) xenial; urgency=medium

  * Upstream release 48.0.2564.109:
- CVE-2016-1622: Same-origin bypass in Extensions.
- CVE-2016-1623: Same-origin bypass in DOM.
- CVE-2016-1624: Buffer overflow in Brotli.
- CVE-2016-1625: Navigation bypass in Chrome Instant.
- CVE-2016-1626: Out-of-bounds read in PDFium.
- CVE-2016-1627: Various fixes from internal audits, fuzzing and other
  initiatives.
  * Upstream release 48.0.2564.116:
- CVE-2016-1629: Same-origin bypass in Blink and Sandbox escape in Chrome.

Date: Thu, 18 Feb 2016 17:55:30 -0500
Changed-By: Chad MILLER 
Maintainer: Ubuntu Developers 
Signed-By: Chris Coulson 
https://launchpad.net/ubuntu/+source/chromium-browser/48.0.2564.116-0ubuntu1.1229
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Format: 1.8
Date: Thu, 18 Feb 2016 17:55:30 -0500
Source: chromium-browser
Binary: chromium-browser chromium-browser-dbg chromium-browser-l10n 
chromium-codecs-ffmpeg chromium-codecs-ffmpeg-dbg chromium-codecs-ffmpeg-extra 
chromium-codecs-ffmpeg-extra-dbg chromium-chromedriver chromium-chromedriver-dbg
Architecture: source
Version: 48.0.2564.116-0ubuntu1.1229
Distribution: xenial
Urgency: medium
Maintainer: Ubuntu Developers 
Changed-By: Chad MILLER 
Description:
 chromium-browser - Chromium web browser, open-source version of Chrome
 chromium-browser-dbg - chromium-browser debug symbols
 chromium-browser-l10n - chromium-browser language packages
 chromium-chromedriver - WebDriver driver for the Chromium Browser
 chromium-chromedriver-dbg - chromium-chromedriver debug symbols
 chromium-codecs-ffmpeg - Free ffmpeg codecs for the Chromium Browser
 chromium-codecs-ffmpeg-dbg - chromium-codecs-ffmpeg debug symbols
 chromium-codecs-ffmpeg-extra - Extra ffmpeg codecs for the Chromium Browser
 chromium-codecs-ffmpeg-extra-dbg - chromium-codecs-ffmpeg-extra debug symbols
Changes:
 chromium-browser (48.0.2564.116-0ubuntu1.1229) xenial; urgency=medium
 .
   * Upstream release 48.0.2564.109:
 - CVE-2016-1622: Same-origin bypass in Extensions.
 - CVE-2016-1623: Same-origin bypass in DOM.
 - CVE-2016-1624: Buffer overflow in Brotli.
 - CVE-2016-1625: Navigation bypass in Chrome Instant.
 - CVE-2016-1626: Out-of-bounds read in PDFium.
 - CVE-2016-1627: Various fixes from internal audits, fuzzing and other
   initiatives.
   * Upstream release 48.0.2564.116:
 - CVE-2016-1629: Same-origin bypass in Blink and Sandbox escape in Chrome.
Checksums-Sha1:
 ab2e7b7ae0276d39cc60370216df3d74e9eec72f 2923 
chromium-browser_48.0.2564.116-0ubuntu1.1229.dsc
 8c3bc85212c20ce70af4972cd7e9f8e9dcb3d1dc 432321192 
chromium-browser_48.0.2564.116.orig.tar.xz
 dfcf10c23fc669a8b051401d35c02af73d3623f4 540744 
chromium-browser_48.0.2564.116-0ubuntu1.1229.debian.tar.xz
Checksums-Sha256:
 f564a4c1100454c84f9c15a0318f68f18f1aca269c6b03a7204635aa5fccad76 2923 
chromium-browser_48.0.2564.116-0ubuntu1.1229.dsc
 6a1eb9b4c853f15eeec0a55af7ac3b41835f0fc592ba6c0a500873cb12a84d0f 432321192 
chromium-browser_48.0.2564.116.orig.tar.xz
 d1c563b27e7808af9c3970a30081f5a9995d15e44b1133b544c8b0d3b986d2cf 540744 
chromium-browser_48.0.2564.116-0ubuntu1.1229.debian.tar.xz
Files:
 6b042f5ece8569e7272ffb0adb29714f 2923 web optional 
chromium-browser_48.0.2564.116-0ubuntu1.1229.dsc
 87d827c19dbc64f20b3494333aedf64b 432321192 web optional 
chromium-browser_48.0.2564.116.orig.tar.xz
 bafc82ee802e37ddf399ffa97461aaa6 540744 web optional 
chromium-browser_48.0.2564.116-0ubuntu1.1229.debian.tar.xz

-BEGIN PGP SIGNATURE-
Version: GnuPG v1

iQEcBAEBAgAGBQJWzEjqAAoJEGEfvezVlG4P80MIAJorwtgqUGjmhgGBAGr09Z4j
4C7LoNyqReegEXsURvlGGh2+sb/WC62IaftUMTuRPeKb5xAaFpAbTTCZTGMuHKwD
DyuhofzIdSpAKBm1A7jDCJ3aAvea9rl5WZmhTSnoLmqlWoC3VR0OKKN3s6OiDno0
GXWWOFkD8R2jukW3jzQL15BLei2ozMx8/AxvCN51D/0FvBVkV118bsOQqhRI67Fa
h0scQw1Kh706K17cz+Ocovge5TJsRWpkrcafg0PnmiWeqZTJiIr+qr16RI4LAfWy
0uG0Y9ZR5/Do3PcPBMljiSJMILqMAo+9BdiEuP3JHNqaEJnLOTZkThPTIVS/+vY=
=GyGE
-END PGP SIGNATURE-
-- 
Xenial-changes mailing list
Xenial-changes@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/xenial-changes


[ubuntu/xenial-proposed] chromium-browser 47.0.2526.106-0ubuntu1.1221 (Accepted)

2016-01-11 Thread Chad MILLER
chromium-browser (47.0.2526.106-0ubuntu1.1221) xenial; urgency=medium

  * Upstream release 47.0.2526.106:
- CVE-2015-6792: Fixes from internal audits and fuzzing.
  * Upstream release 47.0.2526.80:
- CVE-2015-6788: Type confusion in extensions.
- CVE-2015-6789: Use-after-free in Blink.
- CVE-2015-6790: Escaping issue in saved pages.
- CVE-2015-6791: Various fixes from internal audits, fuzzing and other
  initiatives.
- Multiple vulnerabilities in V8 fixed at the tip of the 4.7 branch
  (currently 4.7.80.23).
  * debian/rules: Don't use bundled binutils. Remove execute bits on programs
so we can be sure they aren't run.

Date: Tue, 15 Dec 2015 19:33:00 -0500
Changed-By: Chad MILLER 
Maintainer: Ubuntu Developers 
Signed-By: Chris Coulson 
https://launchpad.net/ubuntu/+source/chromium-browser/47.0.2526.106-0ubuntu1.1221
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Format: 1.8
Date: Tue, 15 Dec 2015 19:33:00 -0500
Source: chromium-browser
Binary: chromium-browser chromium-browser-dbg chromium-browser-l10n 
chromium-codecs-ffmpeg chromium-codecs-ffmpeg-dbg chromium-codecs-ffmpeg-extra 
chromium-codecs-ffmpeg-extra-dbg chromium-chromedriver chromium-chromedriver-dbg
Architecture: source
Version: 47.0.2526.106-0ubuntu1.1221
Distribution: xenial
Urgency: medium
Maintainer: Ubuntu Developers 
Changed-By: Chad MILLER 
Description:
 chromium-browser - Chromium web browser, open-source version of Chrome
 chromium-browser-dbg - chromium-browser debug symbols
 chromium-browser-l10n - chromium-browser language packages
 chromium-chromedriver - WebDriver driver for the Chromium Browser
 chromium-chromedriver-dbg - chromium-chromedriver debug symbols
 chromium-codecs-ffmpeg - Free ffmpeg codecs for the Chromium Browser
 chromium-codecs-ffmpeg-dbg - chromium-codecs-ffmpeg debug symbols
 chromium-codecs-ffmpeg-extra - Extra ffmpeg codecs for the Chromium Browser
 chromium-codecs-ffmpeg-extra-dbg - chromium-codecs-ffmpeg-extra debug symbols
Changes:
 chromium-browser (47.0.2526.106-0ubuntu1.1221) xenial; urgency=medium
 .
   * Upstream release 47.0.2526.106:
 - CVE-2015-6792: Fixes from internal audits and fuzzing.
   * Upstream release 47.0.2526.80:
 - CVE-2015-6788: Type confusion in extensions.
 - CVE-2015-6789: Use-after-free in Blink.
 - CVE-2015-6790: Escaping issue in saved pages.
 - CVE-2015-6791: Various fixes from internal audits, fuzzing and other
   initiatives.
 - Multiple vulnerabilities in V8 fixed at the tip of the 4.7 branch
   (currently 4.7.80.23).
   * debian/rules: Don't use bundled binutils. Remove execute bits on programs
 so we can be sure they aren't run.
Checksums-Sha1:
 f6c1bb5bee5626aa506987aadc3156f89fda58dd 2926 
chromium-browser_47.0.2526.106-0ubuntu1.1221.dsc
 b646acc18bb7e0fea05aae0108abea5660dfde14 1433438428 
chromium-browser_47.0.2526.106.orig.tar.xz
 5925fce11b904790cd3d3e79724978bfc5a3e2ea 541004 
chromium-browser_47.0.2526.106-0ubuntu1.1221.debian.tar.xz
Checksums-Sha256:
 f1578aa790c8f5caff22ce10d0c6818703b58dcbe82a2f439a2e0a038c5c6eeb 2926 
chromium-browser_47.0.2526.106-0ubuntu1.1221.dsc
 64535073330a3d37aad228d10a15cdcbb5b389e59d079d1a3b22d023b99a58e6 1433438428 
chromium-browser_47.0.2526.106.orig.tar.xz
 b8ffdba53e34c5e11736d10827430ccec9b4db4693f2cfc7df0de5db0c57978d 541004 
chromium-browser_47.0.2526.106-0ubuntu1.1221.debian.tar.xz
Files:
 55375400609597de0eb5be117f4250e5 2926 web optional 
chromium-browser_47.0.2526.106-0ubuntu1.1221.dsc
 b61a28c68c8b81b6bfa0fc671faed723 1433438428 web optional 
chromium-browser_47.0.2526.106.orig.tar.xz
 79d3f0ea37d04bd8e4f70c5a765a796b 541004 web optional 
chromium-browser_47.0.2526.106-0ubuntu1.1221.debian.tar.xz

-BEGIN PGP SIGNATURE-
Version: GnuPG v1

iQEcBAEBAgAGBQJWk83fAAoJEGEfvezVlG4PI0oH/i93LkXIFBmL1ICLp7osjaJW
cUcPmZispI2TRYgi7ePyvPQJFS/mAXsGZKTff0zhJJPCdHEg9cFZDtEBfGK9xhJ9
bn4jB/5nM8B1jbCaSRmiki7kB666h/Vizg7M2WjRWtf+YYOx6WffbHyOP57aTG6f
nRrmXA9hjtyclXQpQKXEOXd7X9Ceoj0rWT9HibiLYuM8Y4I3O/rf6YRNZNQ3Z+zl
uByuHbdNbITIVcLTWzzMkxJmUxWoQAgVJnLa1xmt6BO7JdlfVEnWmaEB+QIet13A
/SxScvMbDgaDSsWc60Zw0gH3foEjdljPc4FHFpzY+I5ZovAYB4jQXuqdC+wQZqM=
=Wo3Q
-END PGP SIGNATURE-
-- 
Xenial-changes mailing list
Xenial-changes@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/xenial-changes


[ubuntu/xenial-proposed] chromium-browser 48.0.2564.82-0ubuntu1.1222 (Accepted)

2016-01-25 Thread Chad MILLER
chromium-browser (48.0.2564.82-0ubuntu1.1222) xenial; urgency=medium

  * Upstream release 48.0.2564.82:
- CVE-2016-1612: Bad cast in V8.
- CVE-2016-1613: Use-after-free in PDFium.
- CVE-2016-1614: Information leak in Blink.
- CVE-2016-1615: Origin confusion in Omnibox.
- CVE-2016-1616: URL Spoofing.
- CVE-2016-1617: History sniffing with HSTS and CSP.
- CVE-2016-1618: Weak random number generator in Blink.
- CVE-2016-1619: Out-of-bounds read in PDFium.
- CVE-2016-1620: Various fixes from internal audits, fuzzing and other
  initiatives.
- Multiple vulnerabilities in V8 fixed at the tip of the 4.8 branch
  (currently 4.8.271.17).

Date: Thu, 21 Jan 2016 08:39:10 -0500
Changed-By: Chad MILLER 
Maintainer: Ubuntu Developers 
Signed-By: Chris Coulson 
https://launchpad.net/ubuntu/+source/chromium-browser/48.0.2564.82-0ubuntu1.1222
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Format: 1.8
Date: Thu, 21 Jan 2016 08:39:10 -0500
Source: chromium-browser
Binary: chromium-browser chromium-browser-dbg chromium-browser-l10n 
chromium-codecs-ffmpeg chromium-codecs-ffmpeg-dbg chromium-codecs-ffmpeg-extra 
chromium-codecs-ffmpeg-extra-dbg chromium-chromedriver chromium-chromedriver-dbg
Architecture: source
Version: 48.0.2564.82-0ubuntu1.1222
Distribution: xenial
Urgency: medium
Maintainer: Ubuntu Developers 
Changed-By: Chad MILLER 
Description:
 chromium-browser - Chromium web browser, open-source version of Chrome
 chromium-browser-dbg - chromium-browser debug symbols
 chromium-browser-l10n - chromium-browser language packages
 chromium-chromedriver - WebDriver driver for the Chromium Browser
 chromium-chromedriver-dbg - chromium-chromedriver debug symbols
 chromium-codecs-ffmpeg - Free ffmpeg codecs for the Chromium Browser
 chromium-codecs-ffmpeg-dbg - chromium-codecs-ffmpeg debug symbols
 chromium-codecs-ffmpeg-extra - Extra ffmpeg codecs for the Chromium Browser
 chromium-codecs-ffmpeg-extra-dbg - chromium-codecs-ffmpeg-extra debug symbols
Changes:
 chromium-browser (48.0.2564.82-0ubuntu1.1222) xenial; urgency=medium
 .
   * Upstream release 48.0.2564.82:
 - CVE-2016-1612: Bad cast in V8.
 - CVE-2016-1613: Use-after-free in PDFium.
 - CVE-2016-1614: Information leak in Blink.
 - CVE-2016-1615: Origin confusion in Omnibox.
 - CVE-2016-1616: URL Spoofing.
 - CVE-2016-1617: History sniffing with HSTS and CSP.
 - CVE-2016-1618: Weak random number generator in Blink.
 - CVE-2016-1619: Out-of-bounds read in PDFium.
 - CVE-2016-1620: Various fixes from internal audits, fuzzing and other
   initiatives.
 - Multiple vulnerabilities in V8 fixed at the tip of the 4.8 branch
   (currently 4.8.271.17).
Checksums-Sha1:
 db614829b0ed227f374555bd05b67d79933b9b47 2916 
chromium-browser_48.0.2564.82-0ubuntu1.1222.dsc
 98f18c3e8714cdabfcc39f826e0cbc357ef93fd0 432281684 
chromium-browser_48.0.2564.82.orig.tar.xz
 0f79abaf2e4d027f5cc7f15a33bcaddd6cc02754 540800 
chromium-browser_48.0.2564.82-0ubuntu1.1222.debian.tar.xz
Checksums-Sha256:
 8296df4edb223d1cf8a741c7a5d153430c8c987be7fe02e81c79c2630c21b638 2916 
chromium-browser_48.0.2564.82-0ubuntu1.1222.dsc
 cda64bf427d01bae7d45863812edcd7fa43176238ec07c7752e42afd3e1714fd 432281684 
chromium-browser_48.0.2564.82.orig.tar.xz
 2ee21a47c8dfcbcbef0d99b300d658f6a126e230891c86b099f9cc0487464451 540800 
chromium-browser_48.0.2564.82-0ubuntu1.1222.debian.tar.xz
Files:
 92a2ccf0cc75d84e4218bfc8cfaf63c7 2916 web optional 
chromium-browser_48.0.2564.82-0ubuntu1.1222.dsc
 c121aff107f2d8565352b67ee97a0c47 432281684 web optional 
chromium-browser_48.0.2564.82.orig.tar.xz
 0968577112fe2968bcbe056a0ed03422 540800 web optional 
chromium-browser_48.0.2564.82-0ubuntu1.1222.debian.tar.xz

-BEGIN PGP SIGNATURE-
Version: GnuPG v1

iQEcBAEBAgAGBQJWpo4SAAoJEGEfvezVlG4Py+sH/33u1xNFDNXsENhNUCxwH5LB
G+uG9cqGqXeg8IMKJ3cGlB4O7VhSt+RSFiQXtvuLwt/4FwKbSw/7Swr5NYmiuSgJ
hVhUEk9Q8oMtJiqukW+N0GYwn0Yt1E22FE55lic3zUvxpxsVqrmNs8YyZ+iRcUEh
qwPvA6l2XPCl+2Or2KHHB1JuUGgcGGnBj4R8ZBxV+NgZ+OGIXUg/DgXfPd1Z55kf
3CpOuIgE7bGAGUkNB8Y1YW0tRGUksZtfvUxClLKFshuauCVbdPwxlRFRjQ/8+s06
6v5hskkDdfuykcwDIiU4VMmaWsStaAV1qg5raMUGe83tEBzCfcMOJcN0hauHB54=
=ehca
-END PGP SIGNATURE-
-- 
Xenial-changes mailing list
Xenial-changes@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/xenial-changes


[ubuntu/xenial-proposed] xdg-utils 1.1.1-1ubuntu1 (Accepted)

2016-02-01 Thread Chad MILLER
xdg-utils (1.1.1-1ubuntu1) xenial; urgency=low

  * Merge from Debian unstable. Remaining changes:
- debian/patches/xdg-email-mutt-detect.diff
- debian/patches/xdg-screensaver-restore-timeout.diff
- debian/patches/lp779156-lubuntu.diff
Removed patches because upstream implements:
- xdg-email-envvar.diff
- xdg-open-browser-multiword.diff
- xdg-open-printf.diff
- xdg-screensaver-new-gnome.diff
- no-X.diff
- fix-bashism-use-of-echo.patch
- gnome-3.0.diff
- filenames-with-spaces.patch
  * debian/patches/mimeappslist-file-location: "xdg-mime default"
only set old deprecated mimeapps location. "xdg-mime query default"
retrieved, but nothing could set.  (LP: #1518053)

xdg-utils (1.1.1-1) unstable; urgency=medium

  * New upstream release.
- xdg-open: Handle whitespace in filenames and fix generic mode
  regression. Closes: #801048.
- xdg-screensaver: Reset DPMS timer. Closes: #745340.
  * Update debian/watch, primary URL is working again.
  * Update Description.

xdg-utils (1.1.0-1) unstable; urgency=medium

  * New upstream release.
- Adds references to specifications to the manuals. Closes: #800826.
- xdg-open: Handle files with '?' and '#' in their names in generic mode.
  Closes: #800355.
- xdg-settings: Detect generic DE instead of failing. Closes: #787791.
- xdg-open, xdg-email: Add iceweasel to the list of fallback browsers.
  Closes: #788047.
- xdg-open: Fall back to generic mode if gvfs-open and gnome-open are
  missing. Closes: #685304.
- xdg-mime: Check ~/.config/mimeapps.list for default application.
  Closes: #800825.
  * Don't build html documentation, we don't install it anyway.
  * Update Description.
  * Update Homepage.

xdg-utils (1.1.0~rc3+git20150922-1) unstable; urgency=medium

  * Merge latest upstream git tree.
- xdg-icon-resource: Don't try to install anything into /.
  Closes: #799741.
  * Remove autotests/Makefile in distclean target.

xdg-utils (1.1.0~rc3+git20150919-1) unstable; urgency=medium

  * Rebase on latest upstream git tree.
- Drop the following patches which were applied upstream:
  + xdg-email-detect-icedove.patch
  + xdg-email-thunderbird-quoting.patch
  + xdg-email-try-xdg-open.patch
  + xdg-open-browser-multiword.diff
  + xdg-open-printf.diff
  + fix-bashism-use-of-echo.patch
  * Maintain Debian patches in git instead of using quilt patches.
  * Update git URLs in debian/control.
  * xdg-open: Try $BROWSER first in generic mode if it is set by the
user. Closes: #799568.
  * Add an automated test suite (under development).

xdg-utils (1.1.0~rc3+git20150907-2) unstable; urgency=medium

  * Add upstream bug URL to xdg-open-browser-multiword.diff.
  * Use local variable in patch xdg-open-browser-multiword.diff.
  * Add upstream bug URL to patch xdg-open-printf.diff.
  * Add upstream bug URL to fix-bashism-use-of-echo.patch.
  * Add xdg-email-try-xdg-open.patch: Try using xdg-open in xdg-email's
generic mode. Closes: #691259.
  * Only try to auto-detect Mutt in xdg-email in generic mode after we
tried xdg-open.
  * Add xdg-email-detect-icedove.patch: Also detect Icedove in xdg-email
for Thunderbird special handling.
  * Add xdg-email-thunderbird-quoting.patch: Don't quote header fields
when calling Thunderbird from xdg-email.
  * Drop patch xdg-email-mutt-detect.diff. Currently difficult to pinpoint
exactly when to use auto-detection.

Date: Thu, 28 Jan 2016 09:54:20 -0500
Changed-By: Chad MILLER 
Maintainer: Ubuntu Developers 
Signed-By: Daniel Holbach 
https://launchpad.net/ubuntu/+source/xdg-utils/1.1.1-1ubuntu1
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Format: 1.8
Date: Thu, 28 Jan 2016 09:54:20 -0500
Source: xdg-utils
Binary: xdg-utils
Architecture: source
Version: 1.1.1-1ubuntu1
Distribution: xenial
Urgency: medium
Maintainer: Ubuntu Developers 
Changed-By: Chad MILLER 
Description:
 xdg-utils  - desktop integration utilities from freedesktop.org
Closes: 685304 691259 745340 787791 788047 799568 799741 800355 800825 800826 
801048
Launchpad-Bugs-Fixed: 1518053
Changes:
 xdg-utils (1.1.1-1ubuntu1) xenial; urgency=low
 .
   * Merge from Debian unstable. Remaining changes:
 - debian/patches/xdg-email-mutt-detect.diff
 - debian/patches/xdg-screensaver-restore-timeout.diff
 - debian/patches/lp779156-lubuntu.diff
 Removed patches because upstream implements:
 - xdg-email-envvar.diff
 - xdg-open-browser-multiword.diff
 - xdg-open-printf.diff
 - xdg-screensaver-new-gnome.diff
 - no-X.diff
 - fix-bashism-use-of-echo.patch
 - gnome-3.0.diff
 - filenames-with-spaces.patch
   * debian/patches/mimeappslist-file-location: "xdg-mime default"
 only set old deprecated mimeapps location. "xdg-mime query default"
 retrieved, but nothing could set.  (LP: #1518053)
 .
 xdg-u

[ubuntu/xenial-proposed] chromium-browser 49.0.2623.87-0ubuntu1.1232 (Accepted)

2016-03-21 Thread Chad MILLER
chromium-browser (49.0.2623.87-0ubuntu1.1232) xenial; urgency=medium

  * debian/patches/system-xdg-settings: Insist on using system xdg utilities.
  * Upstream release 49.0.2623.87:
- CVE-2016-1643: Type confusion in Blink.
- CVE-2016-1644: Use-after-free in Blink.
- CVE-2016-1645: Out-of-bounds write in PDFium.
  * Upstream release 49.0.2623.75:
- CVE-2016-1630: Same-origin bypass in Blink.
- CVE-2016-1631: Same-origin bypass in Pepper Plugin.
- CVE-2016-1632: Bad cast in Extensions.
- CVE-2016-1633: Use-after-free in Blink.
- CVE-2016-1634: Use-after-free in Blink.
- CVE-2016-1635: Use-after-free in Blink.
- CVE-2016-1636: SRI Validation Bypass.
- CVE-2015-8126: Out-of-bounds access in libpng.
- CVE-2016-1637: Information Leak in Skia.
- CVE-2016-1638: WebAPI Bypass.
- CVE-2016-1639: Use-after-free in WebRTC.
- CVE-2016-1640: Origin confusion in Extensions UI.
- CVE-2016-1641: Use-after-free in Favicon.
- CVE-2016-1642: Various fixes from internal audits, fuzzing and other
  initiatives.
- Multiple vulnerabilities in V8 fixed at the tip of the 4.9 branch
  (currently 4.9.385.26).
  * debian/rules: No longer fabricate snap package as side effect.
  * debian/control: build-dep on libffi-dev, mesa-common-dev.
  * debian/patches/format-flag: Remove patch.

Date: Tue, 15 Mar 2016 09:42:48 -0400
Changed-By: Chad MILLER 
Maintainer: Ubuntu Developers 
Signed-By: Chris Coulson 
https://launchpad.net/ubuntu/+source/chromium-browser/49.0.2623.87-0ubuntu1.1232
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Format: 1.8
Date: Tue, 15 Mar 2016 09:42:48 -0400
Source: chromium-browser
Binary: chromium-browser chromium-browser-dbg chromium-browser-l10n 
chromium-codecs-ffmpeg chromium-codecs-ffmpeg-dbg chromium-codecs-ffmpeg-extra 
chromium-codecs-ffmpeg-extra-dbg chromium-chromedriver chromium-chromedriver-dbg
Architecture: source
Version: 49.0.2623.87-0ubuntu1.1232
Distribution: xenial
Urgency: medium
Maintainer: Ubuntu Developers 
Changed-By: Chad MILLER 
Description:
 chromium-browser - Chromium web browser, open-source version of Chrome
 chromium-browser-dbg - chromium-browser debug symbols
 chromium-browser-l10n - chromium-browser language packages
 chromium-chromedriver - WebDriver driver for the Chromium Browser
 chromium-chromedriver-dbg - chromium-chromedriver debug symbols
 chromium-codecs-ffmpeg - Free ffmpeg codecs for the Chromium Browser
 chromium-codecs-ffmpeg-dbg - chromium-codecs-ffmpeg debug symbols
 chromium-codecs-ffmpeg-extra - Extra ffmpeg codecs for the Chromium Browser
 chromium-codecs-ffmpeg-extra-dbg - chromium-codecs-ffmpeg-extra debug symbols
Changes:
 chromium-browser (49.0.2623.87-0ubuntu1.1232) xenial; urgency=medium
 .
   * debian/patches/system-xdg-settings: Insist on using system xdg utilities.
   * Upstream release 49.0.2623.87:
 - CVE-2016-1643: Type confusion in Blink.
 - CVE-2016-1644: Use-after-free in Blink.
 - CVE-2016-1645: Out-of-bounds write in PDFium.
   * Upstream release 49.0.2623.75:
 - CVE-2016-1630: Same-origin bypass in Blink.
 - CVE-2016-1631: Same-origin bypass in Pepper Plugin.
 - CVE-2016-1632: Bad cast in Extensions.
 - CVE-2016-1633: Use-after-free in Blink.
 - CVE-2016-1634: Use-after-free in Blink.
 - CVE-2016-1635: Use-after-free in Blink.
 - CVE-2016-1636: SRI Validation Bypass.
 - CVE-2015-8126: Out-of-bounds access in libpng.
 - CVE-2016-1637: Information Leak in Skia.
 - CVE-2016-1638: WebAPI Bypass.
 - CVE-2016-1639: Use-after-free in WebRTC.
 - CVE-2016-1640: Origin confusion in Extensions UI.
 - CVE-2016-1641: Use-after-free in Favicon.
 - CVE-2016-1642: Various fixes from internal audits, fuzzing and other
   initiatives.
 - Multiple vulnerabilities in V8 fixed at the tip of the 4.9 branch
   (currently 4.9.385.26).
   * debian/rules: No longer fabricate snap package as side effect.
   * debian/control: build-dep on libffi-dev, mesa-common-dev.
   * debian/patches/format-flag: Remove patch.
Checksums-Sha1:
 69d4cb2f08ba0be6d0a8975c421859eea7403c2a 2945 
chromium-browser_49.0.2623.87-0ubuntu1.1232.dsc
 16d1a72b0efc39949286dc4885bd6bbfe77d7406 540396 
chromium-browser_49.0.2623.87-0ubuntu1.1232.debian.tar.xz
Checksums-Sha256:
 783d5e7a88ff31beedd2d8ea9a1ea04f12da1471cb9bfc624c327e5e78ca2c06 2945 
chromium-browser_49.0.2623.87-0ubuntu1.1232.dsc
 c7810d6fbae2fc562cb0a74866955acabad63fc6c008737828be4adab075e1d1 540396 
chromium-browser_49.0.2623.87-0ubuntu1.1232.debian.tar.xz
Files:
 de113bfbe4a512c18270563f89bec531 2945 web optional 
chromium-browser_49.0.2623.87-0ubuntu1.1232.dsc
 43eb8f6e2bcabd6a4099d090434118c1 540396 web optional 
chromium-browser_49.0.2623.87-0ubuntu1.1232.debian.tar.xz

-BEGIN PGP SIGNATURE-
Version: GnuPG v1

iQEcBAEBAgAGBQJW8HyRAAoJEGEfvezVlG4PiQIIAIcvPsLVe42eaSohNNVHelwz
NsyAnp4cRrfCJE4O8WSDXPlI+CWUX2hjMBKG0Vo7fzuSsXM9HniV9I6OM5Oj0o0F
5N

[ubuntu/xenial-proposed] chromium-browser 49.0.2623.108-0ubuntu1.1233 (Accepted)

2016-03-29 Thread Chad MILLER
chromium-browser (49.0.2623.108-0ubuntu1.1233) xenial; urgency=medium

  * Upstream release 49.0.2623.108:
- CVE-2016-1646: Out-of-bounds read in V8.
- CVE-2016-1647: Use-after-free in Navigation.
- CVE-2016-1648: Use-after-free in Extensions.
- CVE-2016-1649: Buffer overflow in libANGLE.
- CVE-2016-1650: Various fixes from internal audits, fuzzing and other
  initiatives.
- Multiple vulnerabilities in V8 fixed at the tip of the 4.9 branch
  (currently 4.9.385.33).

Date: Thu, 24 Mar 2016 16:52:52 -0400
Changed-By: Chad MILLER 
Maintainer: Ubuntu Developers 
Signed-By: Chris Coulson 
https://launchpad.net/ubuntu/+source/chromium-browser/49.0.2623.108-0ubuntu1.1233
Format: 1.8
Date: Thu, 24 Mar 2016 16:52:52 -0400
Source: chromium-browser
Binary: chromium-browser chromium-browser-dbg chromium-browser-l10n 
chromium-codecs-ffmpeg chromium-codecs-ffmpeg-dbg chromium-codecs-ffmpeg-extra 
chromium-codecs-ffmpeg-extra-dbg chromium-chromedriver chromium-chromedriver-dbg
Architecture: source
Version: 49.0.2623.108-0ubuntu1.1233
Distribution: xenial
Urgency: medium
Maintainer: Ubuntu Developers 
Changed-By: Chad MILLER 
Description:
 chromium-browser - Chromium web browser, open-source version of Chrome
 chromium-browser-dbg - chromium-browser debug symbols
 chromium-browser-l10n - chromium-browser language packages
 chromium-chromedriver - WebDriver driver for the Chromium Browser
 chromium-chromedriver-dbg - chromium-chromedriver debug symbols
 chromium-codecs-ffmpeg - Free ffmpeg codecs for the Chromium Browser
 chromium-codecs-ffmpeg-dbg - chromium-codecs-ffmpeg debug symbols
 chromium-codecs-ffmpeg-extra - Extra ffmpeg codecs for the Chromium Browser
 chromium-codecs-ffmpeg-extra-dbg - chromium-codecs-ffmpeg-extra debug symbols
Changes:
 chromium-browser (49.0.2623.108-0ubuntu1.1233) xenial; urgency=medium
 .
   * Upstream release 49.0.2623.108:
 - CVE-2016-1646: Out-of-bounds read in V8.
 - CVE-2016-1647: Use-after-free in Navigation.
 - CVE-2016-1648: Use-after-free in Extensions.
 - CVE-2016-1649: Buffer overflow in libANGLE.
 - CVE-2016-1650: Various fixes from internal audits, fuzzing and other
   initiatives.
 - Multiple vulnerabilities in V8 fixed at the tip of the 4.9 branch
   (currently 4.9.385.33).
Checksums-Sha1:
 f0277278277976349f33cc9fd2c54713bcb90758 2952 
chromium-browser_49.0.2623.108-0ubuntu1.1233.dsc
 b976069d7fe1c3872e673ef316751836b61529d7 520440328 
chromium-browser_49.0.2623.108.orig.tar.xz
 52111d633d4201eb4f561aed286847584c784eb8 540472 
chromium-browser_49.0.2623.108-0ubuntu1.1233.debian.tar.xz
Checksums-Sha256:
 a48c66132e2a4028b943ce70bbd04519c066b5483a8ac0a3ad55bb4baf7cd5bb 2952 
chromium-browser_49.0.2623.108-0ubuntu1.1233.dsc
 da083a2bf17ff4c9b09b7451a81dfb41ece6b50ad363df20e918909e8cbcb1c0 520440328 
chromium-browser_49.0.2623.108.orig.tar.xz
 fe408f56ae0aa55683dcd3146e7206c75a835bb657a6a3258c0494c7b897dc17 540472 
chromium-browser_49.0.2623.108-0ubuntu1.1233.debian.tar.xz
Files:
 b770258d456a1ffdfeb8bf980a4652d4 2952 web optional 
chromium-browser_49.0.2623.108-0ubuntu1.1233.dsc
 55a04b64a3a82949ff04eca339e75f7a 520440328 web optional 
chromium-browser_49.0.2623.108.orig.tar.xz
 1e61418a9a8e0ce821fddec861704b2c 540472 web optional 
chromium-browser_49.0.2623.108-0ubuntu1.1233.debian.tar.xz
-- 
Xenial-changes mailing list
Xenial-changes@lists.ubuntu.com
Modify settings or unsubscribe at: 
https://lists.ubuntu.com/mailman/listinfo/xenial-changes