-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 17 Apr 2024 19:43:12 +0100 Source: flatpak Binary: flatpak flatpak-dbgsym flatpak-tests flatpak-tests-dbgsym gir1.2-flatpak-1.0 libflatpak-dev libflatpak0 libflatpak0-dbgsym Architecture: mipsel Version: 1.10.8-0+deb11u2 Distribution: bullseye-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Simon McVittie Description: flatpak - Application deployment framework for desktop apps flatpak-tests - Application deployment framework for desktop apps (tests) gir1.2-flatpak-1.0 - Application deployment framework for desktop apps (introspection) libflatpak-dev - Application deployment framework for desktop apps (development) libflatpak0 - Application deployment framework for desktop apps (library) Changes: flatpak (1.10.8-0+deb11u2) bullseye-security; urgency=high . * d/p/When-starting-non-static-command-using-bwrap-use.patch, d/p/test-run-Add-a-reproducer-for-CVE-2024-32462.patch: Don't allow an executable name to be misinterpreted as a command-line option for bwrap(1). This prevents a sandbox escape where a malicious or compromised app could ask xdg-desktop-portal to generate a .desktop file with access to files outside the sandbox. (CVE-2024-32462) Checksums-Sha1: 41dac1cae68f64da4f73067323480f18bc9e4f88 5937660 flatpak-dbgsym_1.10.8-0+deb11u2_mipsel.deb 0ea307bf2dd87e36c4411f8bc38acb3ef3460d7c 6698576 flatpak-tests-dbgsym_1.10.8-0+deb11u2_mipsel.deb 885c23b814c84bc89fcc0358ad668310e67944ee 745484 flatpak-tests_1.10.8-0+deb11u2_mipsel.deb 8418d3a8e0f4cbd77e5cbe956de802692bd85ade 14592 flatpak_1.10.8-0+deb11u2_mipsel-buildd.buildinfo 00ac14f570058dffa29337b91a9947ad228f9d8c 1134280 flatpak_1.10.8-0+deb11u2_mipsel.deb 271a65cf96d5c2d98bab2b63aa9cfb000769ebde 37700 gir1.2-flatpak-1.0_1.10.8-0+deb11u2_mipsel.deb bba46373c5675384ef407b614951311c08264657 79552 libflatpak-dev_1.10.8-0+deb11u2_mipsel.deb 2641c024465d0dfe2ee53654dd8d8382935162bc 1407056 libflatpak0-dbgsym_1.10.8-0+deb11u2_mipsel.deb 825ca203bf8534821db1f72ff8f1b36d51e43cb7 300352 libflatpak0_1.10.8-0+deb11u2_mipsel.deb Checksums-Sha256: bc6df3510684f5d5f201b61423bf210977cc8792e797121bfe4c4663d9c1f0cf 5937660 flatpak-dbgsym_1.10.8-0+deb11u2_mipsel.deb dfa9e28b013822f46bcec9a2c6b15a72681449a686628b8950fa723843640111 6698576 flatpak-tests-dbgsym_1.10.8-0+deb11u2_mipsel.deb d38d4709f3f9df1c5026228b164fd7ceb2ce4d511d8009eba38e4f3552f2722e 745484 flatpak-tests_1.10.8-0+deb11u2_mipsel.deb f6937b59b1c073b553166c7f37d9651ccd6832d9c4e3d3ea0ee4733430ff7fb6 14592 flatpak_1.10.8-0+deb11u2_mipsel-buildd.buildinfo a7060e4a49396bfb6595ce522327487aa7378dcaf82199e8b2218139571d807b 1134280 flatpak_1.10.8-0+deb11u2_mipsel.deb 4e93a57e0b4a78d243d345d7b89cd6507bbd53e08311c68e09a36ab60ef52fed 37700 gir1.2-flatpak-1.0_1.10.8-0+deb11u2_mipsel.deb 6e051a2b9a899c766a5a98936bd1b20116c2f8fc0f879243c72fa5e06a9a40ea 79552 libflatpak-dev_1.10.8-0+deb11u2_mipsel.deb 54dfc7ccffa17aa6c171eaa7c24f16a21d72d115384f13bca765ab258392a575 1407056 libflatpak0-dbgsym_1.10.8-0+deb11u2_mipsel.deb 91f0cf65107ff54dfbd32b6cf227cdf291ba93e0614dae6991225cd761eba070 300352 libflatpak0_1.10.8-0+deb11u2_mipsel.deb Files: 6c89dc3ecd53099fe86874801893476a 5937660 debug optional flatpak-dbgsym_1.10.8-0+deb11u2_mipsel.deb 7793764b6286e51568d6e62b1fcfa471 6698576 debug optional flatpak-tests-dbgsym_1.10.8-0+deb11u2_mipsel.deb 9d7dc515c301124d5bfc618e99921afd 745484 misc optional flatpak-tests_1.10.8-0+deb11u2_mipsel.deb 9a90b53d7cd3a3883061f8ec58043e86 14592 admin optional flatpak_1.10.8-0+deb11u2_mipsel-buildd.buildinfo f49bac442ce08be7828a3a426f027eb9 1134280 admin optional flatpak_1.10.8-0+deb11u2_mipsel.deb 429f7a1d880002977de185e9630fe0f2 37700 introspection optional gir1.2-flatpak-1.0_1.10.8-0+deb11u2_mipsel.deb 38eed00e0a8f56ce8647f724f24ae9df 79552 libdevel optional libflatpak-dev_1.10.8-0+deb11u2_mipsel.deb 537588355d75ea2104eed9499e71dc8c 1407056 debug optional libflatpak0-dbgsym_1.10.8-0+deb11u2_mipsel.deb 01159ac91aead6df3dc7fc79c69e5c5d 300352 libs optional libflatpak0_1.10.8-0+deb11u2_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEuQAPGkYIXAAfq7z1C2Vm2FYVKKAFAmYhcssACgkQC2Vm2FYV KKDPzw//b08OXBii5VL34T4khQI17/oHvtCb/JykuqNdZxtbjcbwXlDioZQfQv/j eHz1KYlrxvZVMIDiMiu1m0lA9Y2aRVpTOZwRH9FCX6xzwxxXgtemozOsUfwKa3Uh caNus1+H/i+wQ8YtLyWpMfAVNkr0P0uE6iXBnowsT5c35sXMkFdLa6DmI5hlMD7U b84M2uySsMOg/yHf+ExtgV5EF5zMKtvHXT5o+LHkPQKAtouK1UDJ73Am00pf6Bml tjgl2LP4TfESbG4L/l3GJShTmUJXCy4fkO/mwiKvpn9zef2pVwzfLcpLSsio4cPd PxUwcAoItQq3DrHTqCVRbszZfTYOJeAloG9T4GNNE28QTxspAAtq8RTOrTXW6o8F hczu5gHLQL/9aaXhu9Q+F7F2uc2hvjTFMevble/eOvF+F7RQm2vTONhLWerxuoN7 aSAfw1otlGgTR2DGASj2ZnrzOTvpGqHemtKKeeB1e186whfAdnCMHsyyBP9JiHqr 69ZVHi6iwkwKLlbIH19dGhMTmi5kMKEJAAZNM2JlQvSBeLF9muD2y4NW9RnTlPNC KuJDF37/4BcSp9gnDygKfWc47AYgsBG3dG7B2gHVtWwbZGVYkvVAMdqmrLvlh5XB veyTtrYZAhaK/MyZheEnpsZ2J7Hqtps+J3NvVYfsblbzITB/h58= =6cpm -----END PGP SIGNATURE-----