Feeds

Google publishes Chrome patch details

Carpet-bombing fix looks threadbare

Providing a secure and efficient Helpdesk

Google has belatedly released details of a security update to its newly released Chrome browser, days after it actually pushed out the patch.

The update was published on Friday and users of Chrome were automatically updated, but details of the vulnerabilities fixed and performance tweaks only emerged on Monday, via a mailing list posting and a new Google Chrome blog.

Mark Larson, a Google Chrome program manager, writes that Google Chrome Beta version 0.2.149.29 addresses two critical vulnerabilities, a small number of lesser flaws and a variety of performance tweaks.

The first of the two critical bug fixes addresses a buffer overflow bug in handling long filenames, while the second deals with a vulnerability in handling link targets. Both the flaws create a means for hackers to inject hostile code into vulnerable systems, hence their critical rating. The release also fixes a lesser browser crashing bug involved in parsing URLs ending with ":%".

Google has also responded to its exposure to the infamous Safari carpet-bombing flaw by ensuring that desktop is not the default directory for downloads. "This mitigates the risk of malicious cluttering of the desktop with unwanted downloads, which can lead to executing unwanted files," it explains.

Hmm. This is, at best, only a partial workaround, and Google would do far better to address the underlying flaw.

The update also includes a number of performance and stability tweaks including a JavaScript problem involving Facebook, flaws in search suggestions on various sites, and a performance issue involving the Safe Browsing mode.

More details on the update can be found in a posting on the Google Chrome blog here. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
SMASH the Bash bug! Apple and Red Hat scramble for patch batches
'Applying multiple security updates is extremely difficult'
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
Stunned by Shellshock Bash bug? Patch all you can – or be punished
UK data watchdog rolls up its sleeves, polishes truncheon
prev story

Whitepapers

A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.