Google Chrome Board
February 11, 2012, 10:44:02 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Been meaning to throw some schnazz on the forum for some time, and well, it's here!
 
   Home   Help Search Login Register  
Pages: [1]
  Print  
Author Topic: Google Patches Code Execution Security Flaws  (Read 822 times)
TYPELiFE
Administrator
Newbie
*****
Posts: 247




View Profile WWW Email
« on: September 09, 2008, 06:33:37 PM »

Straight from the release notes,

Google has released update patches for the several exploits in the initial release of Google Chrome.

Fixes a buffer overflow vulnerability in handling long filenames that display in the “Save As” dialog. This is a critical risk that could lead to execution of arbitrary code.  See here for fix details.

Fixes a buffer overflow vulnerability in handling link targets displayed in the status area when the user hovers over a link.  This is a critical risk that could lead to execution of arbitrary code.  The issue was reported privately to Google.  Fix details here.

Fixes an out of bounds memory read when parsing URLs ending with :%.  This is a low risk that can be used to crash the entire browser, possibly causing loss of data in the current session. Fix information here.

The update also changes the default Downloads directory if it is set to Desktop to ensure that Desktop cannot be the default. This mitigates the risk of malicious cluttering of the desktop (aka carpet bombing) with unwanted downloads, which can lead to executing unwanted files.

Schwing!
Logged

Patrick Bateman
Newbie
*
Posts: 20




View Profile Email
« Reply #1 on: September 09, 2008, 07:34:11 PM »

I'm glad these issues have been fixed, I was a little afraid of using Google Chrome on my work computer.
Logged

i am what i am
Pages: [1]
  Print  
 
Jump to:  

Powered by SMF 1.1.10 | SMF © 2006-2009, Simple Machines LLC