-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 17 Apr 2024 19:43:12 +0100 Source: flatpak Binary: libflatpak-doc Architecture: all Version: 1.10.8-0+deb11u2 Distribution: bullseye-security Urgency: high Maintainer: all Build Daemon (x86-grnet-02) Changed-By: Simon McVittie Description: libflatpak-doc - Application deployment framework for desktop apps (documentation) Changes: flatpak (1.10.8-0+deb11u2) bullseye-security; urgency=high . * d/p/When-starting-non-static-command-using-bwrap-use.patch, d/p/test-run-Add-a-reproducer-for-CVE-2024-32462.patch: Don't allow an executable name to be misinterpreted as a command-line option for bwrap(1). This prevents a sandbox escape where a malicious or compromised app could ask xdg-desktop-portal to generate a .desktop file with access to files outside the sandbox. (CVE-2024-32462) Checksums-Sha1: bcf837430fd8676141b64dc1bd9cdd3d8542ca15 12654 flatpak_1.10.8-0+deb11u2_all-buildd.buildinfo fca266a8b49e7f793e93022fc58bfc08052ff069 137564 libflatpak-doc_1.10.8-0+deb11u2_all.deb Checksums-Sha256: 10701582b99d043f10da3282266931e871c1107c9623ebb01cc1efb1f76a816d 12654 flatpak_1.10.8-0+deb11u2_all-buildd.buildinfo 9d2ef5c476ffed57e2abad23b89d1dac63fc7623bd4bc4c538655f78af1cbdbc 137564 libflatpak-doc_1.10.8-0+deb11u2_all.deb Files: bf30954b20b539be88b75458afde4d9b 12654 admin optional flatpak_1.10.8-0+deb11u2_all-buildd.buildinfo ade559f12ccb5592fc45b2891942a52f 137564 doc optional libflatpak-doc_1.10.8-0+deb11u2_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEQsM0t1ygJv2xcx3e4cagXJhOTXsFAmYhcf4ACgkQ4cagXJhO TXvGJxAApRU3cruolxRZYKzmCAJDIjsSf+BVDaa0RnCIzlpaZLuwGY/JF21r1ZYy 0Jh+2iKnPAYa0yk6TH4r+uEnyciI7Ceu21X99SEuK5axuB6++6KtiJzbJtzXVvCF 1AKAcPkP6ImC8vfSGmwIUMcF7m8diNaq2a2S0DqZN8/B901WkVVoVJ06pm3WqkZ7 /aRfrRCb+AouagfPvNlyMUrhyQUN7ezw25yYam65divryoXpyW8U5z+SMg7qrm0t tbJkQxs93riGEzNDiafHx7yRw2BAnZjhjzhdTiEpuhGL+L7o0ra4P5cvqbzMHfx3 TQPhxva5eiaVVQzl/T/2OxuN9eaq/IvviRngemRCOqfze5JWI1Uyzi2b7fufZ0d6 5QOSCQNbAyL1+5/Fz1DpFsmen1tlKn46Rn5QxzqxQnp+cvd5LqruOtgeCJajyJ9m xXkOA8b2Ih50qkuvs4Q/FQsb+n1s92KChITTtbr0/GqOCV13mKXWcCLp7oM1HTq0 T8V1Bj4rbn9AizjWToRrDgdeh/gu0WODDaQpE20yJq4wm7wrzYMvK8/dvCGeLUfs KX8IeYoH7NrxI3Zezt/e1TrIMSbkqgCCZuyf0P31V+8NouOX3pRuPzQpp0I83Jqt ITG9ZOcIFFmknrW/58c/zBEBsfFlgWc1JahmwBR45DPYDZhvWQE= =25xQ -----END PGP SIGNATURE-----