Vulnerabilities / Threats
5/16/2012
11:34 AM
Connect Directly
RSS
E-Mail
50%
50%

Google Chrome 19 Debuts, With 20 Bug Patches

Latest release of browser also adds the ability to synchronize open tabs across devices.

Google Drive: 10 Alternatives To See
Google Drive: 10 Alternatives To See
(click image for larger view and for slideshow)
Google Tuesday released version 19 of its Chrome browser, which includes fixes for 20 vulnerabilities, as well as a new feature for sharing open tabs across different devices. But Google said the feature won't be widely available for another few weeks.

The new version of Chrome is available for Windows, Mac, Linux, and Chrome Frame. All current Chrome installations should auto-update to the latest version over the next few days.

Google releases a new, stable version of Chrome about every six to eight weeks.

With the release of Chrome 19, Google also distributed $7,500 as part of its bug bounty program. None of the patched bugs were "critical," meaning--per the Common Vulnerability Scoring System (CVSS)--that attackers could have potentially used them to remotely execute arbitrary code. However, eight of the vulnerabilities patched in the new version of Chrome are of "high" severity, seven are ranked as "medium," and five are of "low" severity.

[ Read It's Browser Version Madness! ]

Six of the bugs were spotted by Google or the broader Chromium (Google Chrome OS) community. A low-risk, Windows-only "bad search path for Windows Media Player plug-in" bug was credited to Microsoft and Microsoft Vulnerability Research.

Full information about all of the bugs has yet to be released; Google typically waits to release detailed information until the majority of Chrome users have received related patches. But many of the patched bugs relate to memory errors in C/C++. Not coincidentally, Google said that a homegrown tool, AddressSanitizer, had been used by researchers to detect many of the patched vulnerabilities.

Unusually, Google also distributed an additional $9,000 in rewards to Aki Helin at the Oulu University Secure Programming Group in Finland, as well as Sławomir Błażek, Chamal de Silva, miaubiz, Arthur Gerkis, and Christian Holler "for working with us during the development cycle and preventing security regressions from ever reaching the stable channel." All feature prominently in Google's Security Hall of Fame, which lists researchers who have helped "make Chromium safer."

Google software engineer and "tab-wrangling server jockey" Raz Mathias explained how Chrome's new tab synchronization feature will work. "When you're signed in to Chrome, your open tabs are synced across all your devices, so you can quickly access them from the 'Other devices' menu on the New Tab page," he said in a blog post. "If you've got Chrome for Android Beta, you can open the same recipe tab right on your phone when you run out to the store for more ingredients. The back and forward buttons will even work, so you can pick up browsing right where you left off."

Chrome isn't the only browser now offering tab synchronization. Notably, Mozilla added tab synchronization to Firefox 4, which it released in 2010.

At this interactive Enterprise Mobility Virtual Event, experts and solution providers will offer detailed insight into how to bring some order to the mobile industry innovation chaos. When you register, you will gain access to live webcast presentations and virtual booths packed with free resources. It happens May 17.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6335
Published: 2014-08-26
The Backup-Archive client in IBM Tivoli Storage Manager (TSM) for Space Management 5.x and 6.x before 6.2.5.3, 6.3.x before 6.3.2, 6.4.x before 6.4.2, and 7.1.x before 7.1.0.3 on Linux and AIX, and 5.x and 6.x before 6.1.5.6 on Solaris and HP-UX, does not preserve file permissions across backup and ...

CVE-2014-0480
Published: 2014-08-26
The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slash) in a URL, which triggers a scheme-relative URL ...

CVE-2014-0481
Published: 2014-08-26
The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a d...

CVE-2014-0482
Published: 2014-08-26
The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.RemoteUserBackend backend, allows remote authenticated users to hijack web sessions via vectors relate...

CVE-2014-0483
Published: 2014-08-26
The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated users to obtain sensitive information via a to_field ...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.