Recent Posts

Community

Email Notifications

Personal Links

Archives

Harry Waldron - IT Security

Security Developments, Software Updates and Best Practices

Google Chrome Browser - Security Update

The new Chrome browser had a security and functional update on September 5th and most users should autoupdate in a transparent fashion.  The "carpet bombing" and a few other issues were resolved in this first update.  Please remember that this is a beta product and it must be used carefully until it's security controls are well established.

Google Chrome - First Security Autoupdate
http://googlechromereleases.blogspot.com/2008/09/beta-release-0214929.html
http://isc.sans.org/diary.html?storyid=5005

QUOTE: Google Chrome version 0.2.149.29 was released on 5 September 2008, and all users are being automatically updated. Automatic updates are a key security feature in helping to ensure the safety of Google Chrome users.

1. Fix a buffer overflow vulnerability in handling long filenames that display in the Save As... dialog.

2. Fix a buffer overflow vulnerability in handling link targets displayed in the status area when the user hovers over a link.

3. Fix an out-of-bounds memory read when parsing URLs ending with :%. This is a low risk that can be used to crash the entire browser, possibly causing loss of data in the current session.

4. Change the default Downloads directory if it is set to Desktop, and ensure that Desktop cannot be the default.

5. Fix a couple of data transfer issues with the Safe Browsing service causing unnecessary traffic.

6. Fix a JavaScript bug that affected facebook.com.

7. Fix search suggestions not working properly on several non-United States sites.

Comments

Free Backgammon said:

It’s the fastest load times I’ve ever seen. It’s very lightweight too … sometimes a good thing, sometimes a bad thing. I’m very lost with finding all the options and stuff without a menu bar. Looks like CTRL + B opens a bookmarks toolbar instead of a bookmarks window.

overall it is quite good.

# October 1, 2008 5:46 AM