-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 17 Apr 2024 19:39:48 +0100 Source: flatpak Binary: flatpak flatpak-dbgsym flatpak-tests flatpak-tests-dbgsym gir1.2-flatpak-1.0 libflatpak-dev libflatpak0 libflatpak0-dbgsym Architecture: s390x Version: 1.14.4-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: s390x Build Daemon (zani) Changed-By: Simon McVittie Description: flatpak - Application deployment framework for desktop apps flatpak-tests - Application deployment framework for desktop apps (tests) gir1.2-flatpak-1.0 - Application deployment framework for desktop apps (introspection) libflatpak-dev - Application deployment framework for desktop apps (development) libflatpak0 - Application deployment framework for desktop apps (library) Changes: flatpak (1.14.4-1+deb12u1) bookworm-security; urgency=high . * d/p/When-starting-non-static-command-using-bwrap-use.patch, d/p/test-run-Add-a-reproducer-for-CVE-2024-32462.patch: Don't allow an executable name to be misinterpreted as a command-line option for bwrap(1). This prevents a sandbox escape where a malicious or compromised app could ask xdg-desktop-portal to generate a .desktop file with access to files outside the sandbox. (CVE-2024-32462) * d/gbp.conf: Use debian/bookworm packaging branch Checksums-Sha1: 8a4bdd1cfe289694ac30c65294f87245cbe1d874 6217656 flatpak-dbgsym_1.14.4-1+deb12u1_s390x.deb 2a0752b19cd7b54f6ff9e1a20d37de5a729964b1 9668708 flatpak-tests-dbgsym_1.14.4-1+deb12u1_s390x.deb 7e33acf9f209fc5cac39ccee6e155f3003ae61ef 1049220 flatpak-tests_1.14.4-1+deb12u1_s390x.deb f5b5a4cd66bcdd256b0a61f3751721a31b1bebea 14220 flatpak_1.14.4-1+deb12u1_s390x-buildd.buildinfo 94f0f93c24223ea7f0ff88c1aaa3464a503c1181 1296212 flatpak_1.14.4-1+deb12u1_s390x.deb 7fdb3cad55641ed0d729daeb9a9bde56f2df0331 22884 gir1.2-flatpak-1.0_1.14.4-1+deb12u1_s390x.deb 3b6ef87659459d3d4a62baecd0f0a2c14514b0eb 66412 libflatpak-dev_1.14.4-1+deb12u1_s390x.deb 30f4e8a21225d52abded122c828f6337695b5498 1502456 libflatpak0-dbgsym_1.14.4-1+deb12u1_s390x.deb 5b8573ee2b02165b11097ffbb5eeb41332a670b5 321640 libflatpak0_1.14.4-1+deb12u1_s390x.deb Checksums-Sha256: 018bac97f775dadd32bbbce17f362c1324a2ba6f4c6b49b93da605feafb60a35 6217656 flatpak-dbgsym_1.14.4-1+deb12u1_s390x.deb 85fd03e9ceed4de16ba7caa1041ee31ec6ac20d7e566ac130e8161ab0a44e787 9668708 flatpak-tests-dbgsym_1.14.4-1+deb12u1_s390x.deb 24d6a90f115223f0f672570b0f30c5b664da6abfa021bf0ef97145891f70b489 1049220 flatpak-tests_1.14.4-1+deb12u1_s390x.deb 6c38895f5fba1538d38152e0b72733e4c0490996309f05153ef45819d28d0cf8 14220 flatpak_1.14.4-1+deb12u1_s390x-buildd.buildinfo 9d9926585b687983f2fb6707ba24eed8425dea928abc61e525c17a6767c26470 1296212 flatpak_1.14.4-1+deb12u1_s390x.deb 473aab52b38f7c6709edb7612119b7e3a716ff18cfff53adff3b6d903ccf7c4b 22884 gir1.2-flatpak-1.0_1.14.4-1+deb12u1_s390x.deb 2d1c38389be71b44a607f5758894f3396a949fe901ab9f9f05f4ad2d90134375 66412 libflatpak-dev_1.14.4-1+deb12u1_s390x.deb 2f882d7db082f24c293d41298e2ead47501151a9597c5fdce7a2a10b4f4ed874 1502456 libflatpak0-dbgsym_1.14.4-1+deb12u1_s390x.deb d04c8fe279ff6e844bf1f59db9ec889fec2af27e095e4d09ffc75e060d36bad3 321640 libflatpak0_1.14.4-1+deb12u1_s390x.deb Files: 9c8aeae8325163020c52ef9076e728fd 6217656 debug optional flatpak-dbgsym_1.14.4-1+deb12u1_s390x.deb e5de6d7f11a56afff7a626e73a7367a1 9668708 debug optional flatpak-tests-dbgsym_1.14.4-1+deb12u1_s390x.deb f77e94049fae0839a676a5b3ffd7bad1 1049220 misc optional flatpak-tests_1.14.4-1+deb12u1_s390x.deb 1b078d87fb8dbf517e8ad8793553bf9a 14220 admin optional flatpak_1.14.4-1+deb12u1_s390x-buildd.buildinfo 09a245866c0a0dc122333ee0c90a7ff9 1296212 admin optional flatpak_1.14.4-1+deb12u1_s390x.deb 536051a1bb55b58633ca9f314f41665a 22884 introspection optional gir1.2-flatpak-1.0_1.14.4-1+deb12u1_s390x.deb f4174f2e3d8ca590b32543d167c7a95f 66412 libdevel optional libflatpak-dev_1.14.4-1+deb12u1_s390x.deb 8cb903216199373fa82c1917662f87f4 1502456 debug optional libflatpak0-dbgsym_1.14.4-1+deb12u1_s390x.deb 445f24749221df502d56b5bf8eee6d05 321640 libs optional libflatpak0_1.14.4-1+deb12u1_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEETdQgQHyJW2hcXsTC6b+AMjGgQHgFAmYhcokACgkQ6b+AMjGg QHjFlQ/9Fm7pc4Nc6W6KI9/Kc//mJXJxE7+rS0lRRz8hxbLomCkZdT+85MTBY0s8 gVJYOkA6cihgpALTv0zzBVZpuyKI/51q9kD/3TKYuR4C/WpA/d03hTjlx09OjHI1 /ikyJ9XQi800ajZg6B2beLOQ/WSCNttvdte1LaV7quDPMAAVMVHKh+rxpausc8O1 skXdD1PJ0M67xdgNdKq4b2zQSK8z2EutY2U35ISZnQcJI9R8nEZjhJ6cDoX5gCdV zBEilGtvN6LkLLR+iAFpE9VLxlNQkgW6gBaXBCb/tWFmvmzgCKoNXAbCahCu2cGB 1I2ZwLMWIv1D8Hox0KXxHna1w0HASxujqL9ipHNs0L5OjSxMdsKZZq9Tol6/hNRc +WyKxKXlZEhS13Keym2FMNXEXjZmc4S1/aptRBFCfWfMft8tqwXGnBPddimieT3I w+H8Rkqqxl6JbG3xMWrQXBo1Bq940D4G0/sz95RNpqcU8SPLDdxbgozBUN0uKHj4 cFjM1JjCf3OjpLzBWQPgVYZAf8hgRRfFbe2kRl2kF4fBC2PzTI9+X4K7VHSbWzNc IW15ZeTNMuoWyTJrg0tVRUkA6CwvsAeMHLeRGzwxyWmxXA2MBhmv+MK9MYkRGuXH jx3PF4T0ooNFD9d+d83P8BFNsxwkVR6Hw9GfYzD0Y33pgdbQg3I= =Y+E1 -----END PGP SIGNATURE-----