-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 17 Apr 2024 19:43:12 +0100 Source: flatpak Binary: flatpak flatpak-dbgsym flatpak-tests flatpak-tests-dbgsym gir1.2-flatpak-1.0 libflatpak-dev libflatpak0 libflatpak0-dbgsym Architecture: s390x Version: 1.10.8-0+deb11u2 Distribution: bullseye-security Urgency: high Maintainer: s390x Build Daemon (zani) Changed-By: Simon McVittie Description: flatpak - Application deployment framework for desktop apps flatpak-tests - Application deployment framework for desktop apps (tests) gir1.2-flatpak-1.0 - Application deployment framework for desktop apps (introspection) libflatpak-dev - Application deployment framework for desktop apps (development) libflatpak0 - Application deployment framework for desktop apps (library) Changes: flatpak (1.10.8-0+deb11u2) bullseye-security; urgency=high . * d/p/When-starting-non-static-command-using-bwrap-use.patch, d/p/test-run-Add-a-reproducer-for-CVE-2024-32462.patch: Don't allow an executable name to be misinterpreted as a command-line option for bwrap(1). This prevents a sandbox escape where a malicious or compromised app could ask xdg-desktop-portal to generate a .desktop file with access to files outside the sandbox. (CVE-2024-32462) Checksums-Sha1: 7f664785a0c14cd7418f5e80fc40387f5f6d7370 6243232 flatpak-dbgsym_1.10.8-0+deb11u2_s390x.deb 0c35cab1f1069a52a76d9cc50b0fda8966e2c1f3 7007980 flatpak-tests-dbgsym_1.10.8-0+deb11u2_s390x.deb ced779fe3c725529db7a080faa630f7543596024 822180 flatpak-tests_1.10.8-0+deb11u2_s390x.deb 93bf9d66cc079262d260b191d5d94340d260aba0 14653 flatpak_1.10.8-0+deb11u2_s390x-buildd.buildinfo 811b3022a91be3cedd8f542eb50599ead05c5b63 1205084 flatpak_1.10.8-0+deb11u2_s390x.deb a2718d8b57284d1a47a296aebd33c3ae150a649e 37576 gir1.2-flatpak-1.0_1.10.8-0+deb11u2_s390x.deb 4f42f70b2afead39581c8a020cde6120723ed12d 79544 libflatpak-dev_1.10.8-0+deb11u2_s390x.deb b44bdf879b16e28c45e889a5d079cd9fa3d24d7a 1476532 libflatpak0-dbgsym_1.10.8-0+deb11u2_s390x.deb aeec70a4b74a68dc076f0d282134f9dd8b53258e 317624 libflatpak0_1.10.8-0+deb11u2_s390x.deb Checksums-Sha256: 51ada66ef9a68b454841028e5dbbf7ebd3199dd1b6729f1ecabde662239ff3d2 6243232 flatpak-dbgsym_1.10.8-0+deb11u2_s390x.deb c6c2b96de56c752278038e153c735c21f6c296e116d2e025202ec8f73c065b26 7007980 flatpak-tests-dbgsym_1.10.8-0+deb11u2_s390x.deb e27925454101cba9bc5c03075b674dc5c98c90ed74ccae7c9e29e19876599be3 822180 flatpak-tests_1.10.8-0+deb11u2_s390x.deb ca899f3d234645ab1a57c5abbea3590216bb007ba3ae774c9f742eaa4b6a1d1c 14653 flatpak_1.10.8-0+deb11u2_s390x-buildd.buildinfo 649cd6d066d00edd9dff7f33a5d713bb7e5aba7f7c684b15685609c744c8323f 1205084 flatpak_1.10.8-0+deb11u2_s390x.deb 6d3b03268b9446c0951808191bd3027bd85473955bd781efad58f31e81ca9b4a 37576 gir1.2-flatpak-1.0_1.10.8-0+deb11u2_s390x.deb 526b1e64c978b7b9e9a66e0a3b730d5c4655e794b9a0f6df2439dfe4e540bbd6 79544 libflatpak-dev_1.10.8-0+deb11u2_s390x.deb d23cd769b8c008d4f94fceefe39f7135d8db7106839297d0b36674c1f6b962f1 1476532 libflatpak0-dbgsym_1.10.8-0+deb11u2_s390x.deb 27b77fe07b2d01bae8efea0146483456ac53ef73fc9a957356ce540a2959c093 317624 libflatpak0_1.10.8-0+deb11u2_s390x.deb Files: 891b13c8250a1259f3aea1e56c86aa4a 6243232 debug optional flatpak-dbgsym_1.10.8-0+deb11u2_s390x.deb 5fcebdfc7a0d28ddd57c51ddc7a57745 7007980 debug optional flatpak-tests-dbgsym_1.10.8-0+deb11u2_s390x.deb b9a83c7eba155463067dbfce855c7b1b 822180 misc optional flatpak-tests_1.10.8-0+deb11u2_s390x.deb a1b6e8c196da02b23335fce5e19c9bcd 14653 admin optional flatpak_1.10.8-0+deb11u2_s390x-buildd.buildinfo fef3d36bde73868665697b365f72fcfe 1205084 admin optional flatpak_1.10.8-0+deb11u2_s390x.deb df650abd40478f148ebcf0ffc4d66c65 37576 introspection optional gir1.2-flatpak-1.0_1.10.8-0+deb11u2_s390x.deb e08e1b81b8685178779e1124395e2823 79544 libdevel optional libflatpak-dev_1.10.8-0+deb11u2_s390x.deb bb0fb0d2e04a68303749b001affe0d7f 1476532 debug optional libflatpak0-dbgsym_1.10.8-0+deb11u2_s390x.deb 778c28cbbcacf2055b4754c376f85d6b 317624 libs optional libflatpak0_1.10.8-0+deb11u2_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEETdQgQHyJW2hcXsTC6b+AMjGgQHgFAmYhcgMACgkQ6b+AMjGg QHjt8A//aNZqIn0DUG/IHEPrCVaUBRGMJIoF3J2S2q26v3fn9g2x0Ng/5NxOq3vV 4YRWeAVlA5dpVnXAUGzKI5uSzpZPUQ4OFZ/p5/NKcw2s6o6ruozzGGqKzYeaqC6E 4ZcbM0e6xHYd6X2G/JHxBXAP8XVUAc/RlSvwE+BpWvnMWMcDeVbAv0P7ME1l2AZ1 Vh+tx1mngCxLJXD6fh64ryiRGfgEGR15/PWsO0N/TFaVCS1jRfjYWSSnHTO3Fl0U qD9LaqGk/Y80d1YJnxFPrBSL4PQjEh0FFStKtm5Ehc4ETOyhjkEG6gaF6zwDjztl 7SgYvb+9S7cSt+ll802NRILU90R3Mk/66o0ibvEsxyxYf9mJqy99xbRkTfMQTyh5 G1SUCq1KLG8ovK+XsP6sjUtiVaExW7IIJPuc6EIwwgWmy2sDB3e3JOxmFZQDrkkM K78XWdozEPaS3/ILAhxiGzjMrIFWxtWpTASNrRg4q6U813A8MkGA7t8YOi8XUT5m z0/Al0/xxGKtvUarIhTw4Edo5T6j8Ju+ISBG08JVQEPPAlR/omgzVKgiNKc6hNGs OwuqXqRa7BjEUo5aYpzPLCb/mbuV4BpfsM67n73f3jRtVsF0dUPrFEmAzMIKteg9 PsOSOG9n/3PrMaR2dXmvlGuwpWD2L+wwWt2he9ZwMRBi0FIv9EM= =JWVh -----END PGP SIGNATURE-----