-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 17 Apr 2024 19:39:48 +0100 Source: flatpak Binary: flatpak flatpak-dbgsym flatpak-tests flatpak-tests-dbgsym gir1.2-flatpak-1.0 libflatpak-dev libflatpak0 libflatpak0-dbgsym Architecture: ppc64el Version: 1.14.4-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-osuosl-01) Changed-By: Simon McVittie Description: flatpak - Application deployment framework for desktop apps flatpak-tests - Application deployment framework for desktop apps (tests) gir1.2-flatpak-1.0 - Application deployment framework for desktop apps (introspection) libflatpak-dev - Application deployment framework for desktop apps (development) libflatpak0 - Application deployment framework for desktop apps (library) Changes: flatpak (1.14.4-1+deb12u1) bookworm-security; urgency=high . * d/p/When-starting-non-static-command-using-bwrap-use.patch, d/p/test-run-Add-a-reproducer-for-CVE-2024-32462.patch: Don't allow an executable name to be misinterpreted as a command-line option for bwrap(1). This prevents a sandbox escape where a malicious or compromised app could ask xdg-desktop-portal to generate a .desktop file with access to files outside the sandbox. (CVE-2024-32462) * d/gbp.conf: Use debian/bookworm packaging branch Checksums-Sha1: 248f11e47eb7d3f77252dadff89718e1cee15aae 6477428 flatpak-dbgsym_1.14.4-1+deb12u1_ppc64el.deb 866f6f87ab1c74b268243c4234fb7849866ddce3 10105276 flatpak-tests-dbgsym_1.14.4-1+deb12u1_ppc64el.deb 2c9f4c4a7c10554a02103763e24ba858e03ce6c7 1186764 flatpak-tests_1.14.4-1+deb12u1_ppc64el.deb 58addf22d3d4c814691be7bfd80444ac879e48fc 14399 flatpak_1.14.4-1+deb12u1_ppc64el-buildd.buildinfo d37de9f750e6bd57fe3480eb326b2c4f8662b88d 1416644 flatpak_1.14.4-1+deb12u1_ppc64el.deb 4258f337e41defaefec8b971c681ffe323280b14 23040 gir1.2-flatpak-1.0_1.14.4-1+deb12u1_ppc64el.deb 7799cb37c477b0c7dd6484e81fb88bc00e13c183 66420 libflatpak-dev_1.14.4-1+deb12u1_ppc64el.deb 8ec4cb104fb28c99702df22efb699676a5f65c34 1566204 libflatpak0-dbgsym_1.14.4-1+deb12u1_ppc64el.deb 071cd64ab21b9f9958dfce10bef918ce3417bcb9 377976 libflatpak0_1.14.4-1+deb12u1_ppc64el.deb Checksums-Sha256: 0db6319c64c52dd514e8cb10dd31beeed8e549fb44daf6ae9c6343dcb66a0f44 6477428 flatpak-dbgsym_1.14.4-1+deb12u1_ppc64el.deb c7bb6bff6bf6631e0756c10061dc212e5c526cc4fe4c006683a1128906cb0582 10105276 flatpak-tests-dbgsym_1.14.4-1+deb12u1_ppc64el.deb bcac9b569c45dc6475176607c492b7dec8c8a23d16f3eafca4cf6df8cf19a268 1186764 flatpak-tests_1.14.4-1+deb12u1_ppc64el.deb 5f225dbb3e9631ede265a3bef31e9e0ddcfa8b3e45e55f091489b174044810a6 14399 flatpak_1.14.4-1+deb12u1_ppc64el-buildd.buildinfo 7d5c9d047e52eb72996ea958ab16d693d2fbe77120f6153ee509c61f59501066 1416644 flatpak_1.14.4-1+deb12u1_ppc64el.deb 4f97781bad73e829a73c1863d6cbd52a50d722ba4c6572bd11a19d9ab36ec2a1 23040 gir1.2-flatpak-1.0_1.14.4-1+deb12u1_ppc64el.deb fb1068b2808a5b39491812774238f0a1f80d31469f2b0a2bd66b971224c0c0a5 66420 libflatpak-dev_1.14.4-1+deb12u1_ppc64el.deb 4577f92efd50b9743e09f6e3f70b61f6e4abb68b0d17092eebd7ee0c6e245c8e 1566204 libflatpak0-dbgsym_1.14.4-1+deb12u1_ppc64el.deb b6bf1e24005baae2eefcd894323d81d69ca456ba36e39404215279e0b8f8afa8 377976 libflatpak0_1.14.4-1+deb12u1_ppc64el.deb Files: 6e6bb934a68ea1566ed7e6840281d3ba 6477428 debug optional flatpak-dbgsym_1.14.4-1+deb12u1_ppc64el.deb 2159e92dcacedd99bc5001b76f1638ed 10105276 debug optional flatpak-tests-dbgsym_1.14.4-1+deb12u1_ppc64el.deb 598e07dd1252f1297d52118a353fcf11 1186764 misc optional flatpak-tests_1.14.4-1+deb12u1_ppc64el.deb 85331f4058b5875fc682666623144888 14399 admin optional flatpak_1.14.4-1+deb12u1_ppc64el-buildd.buildinfo 398838fbb645f15f2ea4ea33475d3891 1416644 admin optional flatpak_1.14.4-1+deb12u1_ppc64el.deb f1fa93868cb7ae5a2cd7156b2cdff112 23040 introspection optional gir1.2-flatpak-1.0_1.14.4-1+deb12u1_ppc64el.deb b8a9df1d13f0a3280dba849e10a97491 66420 libdevel optional libflatpak-dev_1.14.4-1+deb12u1_ppc64el.deb 5ef8ff65b53ab61367bbb8669ea06d28 1566204 debug optional libflatpak0-dbgsym_1.14.4-1+deb12u1_ppc64el.deb d3abd75945c5943133464f86cbfd91ea 377976 libs optional libflatpak0_1.14.4-1+deb12u1_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5hbnFkJlczvLwwS0Y7DdE4sWZ/UFAmYhcikACgkQY7DdE4sW Z/UjQhAAoIzHe1ay1fLJ4R+CNJ17W6JBOX0UZQtzr84c5KC7yN+gSRQvTEH74ZMr B9F4a5WyZI7KQtEzR+OxPQq1vxcaXUEUCwQOg7G2HoDu6Qhw3X/Y0tXDJU3xl7e3 Eg/A54nJMheJpLoDhpTrEyqv/t0OJ95EXugCH+ojfGC42LWe4USshF3cHoZ0pVzu NPXhWSC+RJ/XRbYKtaBlkHZUtbR5PIJPG1Fo0Uam4zTyFRK7SEXAqvhwYM+bwzT4 rrFf/d5OaFyuccW7sEaqZ93RCmDfDP+UV8LKCVJuxdTX7uomSodHpj6VhlhMQ5vc kMfwK6A50g3lhbnM94NmvjwIwG15qg+8ysAPiLmgqB2Ed2BDQsSA28HrYx9fZcBx Df60maElMdqeaUdwVZQmZERQVKTs2GIShu/1h3Im3J013hkE4U0rmrTwBTgHaucL oNDiYGt/8C3LfxzXn7LbffjC8fQpDQiCS7lvGW/g9eUEP3Wx+K2v/ZqwXx2CXjxY API56MD0A8C3/dWCA1NaZAi+U0ULHYAJjaYI8VmGFeDUzx/Fwee78WRcyxTBJCNZ 50be2uQ++ad0TtKDioApwnvGTaB8KJhbR7J918lp8rGPDgamY0aVRzjgKZBzvEpr m4vK75p2SD+Wp8sJTu5Dp8zAa5f1YbUDUpiwpiuvVd8vS5X3fAI= =v6Hr -----END PGP SIGNATURE-----