-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 17 Apr 2024 19:43:12 +0100 Source: flatpak Binary: flatpak flatpak-dbgsym flatpak-tests flatpak-tests-dbgsym gir1.2-flatpak-1.0 libflatpak-dev libflatpak0 libflatpak0-dbgsym Architecture: ppc64el Version: 1.10.8-0+deb11u2 Distribution: bullseye-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-conova-01) Changed-By: Simon McVittie Description: flatpak - Application deployment framework for desktop apps flatpak-tests - Application deployment framework for desktop apps (tests) gir1.2-flatpak-1.0 - Application deployment framework for desktop apps (introspection) libflatpak-dev - Application deployment framework for desktop apps (development) libflatpak0 - Application deployment framework for desktop apps (library) Changes: flatpak (1.10.8-0+deb11u2) bullseye-security; urgency=high . * d/p/When-starting-non-static-command-using-bwrap-use.patch, d/p/test-run-Add-a-reproducer-for-CVE-2024-32462.patch: Don't allow an executable name to be misinterpreted as a command-line option for bwrap(1). This prevents a sandbox escape where a malicious or compromised app could ask xdg-desktop-portal to generate a .desktop file with access to files outside the sandbox. (CVE-2024-32462) Checksums-Sha1: f751fef8bae1674453ed754aa572162eae950ed4 6166724 flatpak-dbgsym_1.10.8-0+deb11u2_ppc64el.deb d79e31816bf1ce245fdac7bf2bb14591006a57f9 6956984 flatpak-tests-dbgsym_1.10.8-0+deb11u2_ppc64el.deb db24bee74ca541ae0bf7e8a07988429b0fbc1d8a 924892 flatpak-tests_1.10.8-0+deb11u2_ppc64el.deb 6a7771b45bf20a00ede7504840be96422fef5a4a 14771 flatpak_1.10.8-0+deb11u2_ppc64el-buildd.buildinfo 7f532b7525d30ae44f0d9bb32ebe050451fdb7b3 1320232 flatpak_1.10.8-0+deb11u2_ppc64el.deb a412a42d096087b6e7698eaa031dcf20ba62c5f5 37704 gir1.2-flatpak-1.0_1.10.8-0+deb11u2_ppc64el.deb c964afd8c04e9c1217e598849810ea63bc973856 79560 libflatpak-dev_1.10.8-0+deb11u2_ppc64el.deb 079bf423ab975053ad00e575b4ba7e1d0b0dfb2c 1467340 libflatpak0-dbgsym_1.10.8-0+deb11u2_ppc64el.deb cff929122cc50b2cffea7d65f3445a48a79611bb 367508 libflatpak0_1.10.8-0+deb11u2_ppc64el.deb Checksums-Sha256: 6d7cb8b298609e4b69a736c4c2a427f4e945c67d311d0162b7c51c5ca3ae8fe0 6166724 flatpak-dbgsym_1.10.8-0+deb11u2_ppc64el.deb ba5973ff49ca5a6123376e6a289d8a16e6b72ee2e5c9173f04b0abfa2a2d9d6d 6956984 flatpak-tests-dbgsym_1.10.8-0+deb11u2_ppc64el.deb 3fb15cb5c0e50694da1bfcbded0a1e37a701707595230f4ee4bb17dc1c0df945 924892 flatpak-tests_1.10.8-0+deb11u2_ppc64el.deb 0827c7a9efcd844da79938485c45ca4b960a6e3ba1e91ea37b47ed48c774a216 14771 flatpak_1.10.8-0+deb11u2_ppc64el-buildd.buildinfo bff1a4d89c7fde0e087474be4354daa476d867393f467cbe439fa3bfe0fcd23a 1320232 flatpak_1.10.8-0+deb11u2_ppc64el.deb aa33ccf9a04316dc9524f2a6dc7e568f54007f646d8b853b318235c2e284feba 37704 gir1.2-flatpak-1.0_1.10.8-0+deb11u2_ppc64el.deb ac7c61686c2ac46b7095c8a5bc266f6007f50164dc8aac620c8e75ff98f004b2 79560 libflatpak-dev_1.10.8-0+deb11u2_ppc64el.deb 8b56ceedaad919e86c907c7b712013f5155875396895b9c845c8ee4423627fcd 1467340 libflatpak0-dbgsym_1.10.8-0+deb11u2_ppc64el.deb 06bb7ee915527dacc931132a08552d85a8ef3159770a352c7c5758dcea0cb889 367508 libflatpak0_1.10.8-0+deb11u2_ppc64el.deb Files: d3ce621adfde0f7f967fe6e212639162 6166724 debug optional flatpak-dbgsym_1.10.8-0+deb11u2_ppc64el.deb a9294e40ae7f6d4ac4696167f365412a 6956984 debug optional flatpak-tests-dbgsym_1.10.8-0+deb11u2_ppc64el.deb f299d047a66e9904fa43b85313cf2b78 924892 misc optional flatpak-tests_1.10.8-0+deb11u2_ppc64el.deb fd6352032a9fdc8ed3056e544797f66e 14771 admin optional flatpak_1.10.8-0+deb11u2_ppc64el-buildd.buildinfo fc09394aad4e3ddeee5640917b2031aa 1320232 admin optional flatpak_1.10.8-0+deb11u2_ppc64el.deb ca12b3e5849ada334bc676bc1f440d22 37704 introspection optional gir1.2-flatpak-1.0_1.10.8-0+deb11u2_ppc64el.deb f45ef63b6c89a8136296d49d88710b3e 79560 libdevel optional libflatpak-dev_1.10.8-0+deb11u2_ppc64el.deb c552d2e6702f5425eadd73d130b23851 1467340 debug optional libflatpak0-dbgsym_1.10.8-0+deb11u2_ppc64el.deb 56712fcbc7b5f90532bfb0b754bd272d 367508 libs optional libflatpak0_1.10.8-0+deb11u2_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE8YyVP0bbbFwKPsGN0jKBgzfto4IFAmYhcgQACgkQ0jKBgzft o4JYtxAAgpWRBRedkl0ItihKEXjGZEPgk3/oBoEd/JY6DM8cnMlL/BUFYQVbnpai bVTIzw86ApBvHf223rBqprHXITzvQmQbyvQRQiD1tvGnZ96I8r+jT+8j2ikMlS+Q 655qKhaL2WDnfC0WwyM3NYg65YDJjV6gzN32w5+1LBXGZVP7w2iXql82DXgGnk6v pZV0eHB5+n845amPsmEzSJEC09dMcCLFCCu9JTox277xmKjOkmLmy/2ofBPtwJu9 alDGZ4EOS1uJg0j1/GLWVaziDW4dNml+P95XZR1KLHb99yN+Qpi/2GQuA6wTVUne U9HvdFrO8YYYmK+gFaRy8sNwwJGqc3Aspc9o1CSlH1EpKwruUuv8zrB2AXkc+f8F BsLgYh2uT+biidNP4Vz0kq3SEyd9t9NLth98xHuXgcyJrvN5LU1f/b9VcJVOawE3 W1XxlA9fYTi6tqjbCM01UCZys+OLKSWPElamyn4qhGWeImTK3lwRr0mZcarK0ZmB 7Wpyi3GfHeRH0TMwTyfO1GrKXRRjgczcwZAqu3KzGaYJtrGax0rU0Y2YIDYBQoDA eMS03siykpI665lISK0Q9FqWECBKvOlp1ia5usKVzAPhpf7uDH6itIxC6Vtx1771 BQZ1d62RaRFlGv+5Tl90qRO0ITxo6ot9mlFnJck5ZxZcYRf9Db4= =Y50B -----END PGP SIGNATURE-----