Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - We'e your CTRL+D site.. right?.. RIGHT?

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews



IObit Black Friday Sale

spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Macrium Reflect FREE Edition
3. Smart Defrag
4. MusicBee
5. Sergei Strelec's WinPE
6. Microsoft Visual C++ 2015-2022 Redistributable Package
7. Visual C++ Redistributable Runtimes AIO Repack
8. McAfee Removal Tool (MCPR)
9. K-Lite Mega Codec Pack
10. Tweaking.com - Windows Repair
More >>

top reads

Star All the New Features Landing in Windows 11 This December

Star Lossless vs Lossy: When FLAC, APE, and ALAC Beat MP3 and When They Don't

Star Google Search Tricks You'll Actually Use in 2025 and Beyond

Star Fresh PC Checklist: First 12 Things to Do On a New Windows 11 Machine

Star Running AI Models Locally: What They Are, Where to Find Them, and How to Get Started

Star Deciding Between Idle State, Sleep Mode, and Shutdown: What's Best for Your PC?

Star How to Fix VMware Workstation "The Update Server Could Not Be Resolved" Error Installing VMware Tools

Star How to Remove Google Gemini from Your Phone (and Your Life)

Star Windows Bloat Removal Guide: Debloat Safely and Keep What You Need

Star Windows 11 Repair Playbook: SFC, DISM, CHKDSK Without Breaking Stuff


MajorGeeks.Com » News » December 2012 » Two High-Risk Flaws Fixed in Google Chrome 23

Two High-Risk Flaws Fixed in Google Chrome 23


Contributed by: Email on 12/03/2012 03:19 PM [ comments Comments ]


Google has fixed two bugs in its Chrome browser, including a high-severity vulnerability in its media handler that a researcher named Pinkie Pie discovered. The bug, which is different from another use-after-free vulnerability the researcher used in the Pwnium contest at Hack in the Box in October, was serious enough to earn him a bug bounty of more than $7,000.

Google repaired the two high-priority vulnerabilities in Chrome 23, pushing out the new version to users late last week. The company has been very quick to fix security vulnerabilities, especially those that have been made public or come out of contests such as Pwn2Own or the company's own Pwnium, which gives researchers monetary incentives for finding particularly severe flaws in the browser during a set period of time at a conference. The first of the Pwnium contests, which was at CanSecWest in Vancouver earlier this year, produced two sets of bugs from separate researchers who were able to produce full sandbox escapes and compromises of Chrome.

Google patched all of those vulnerabilities within a couple of days of their discovery, and was able to do the same with the other bugs that Pinkie Pie used in the second Pwnium contest at Hack in the Box in October. The company recently said that it would be handing out some larger-than-usual rewards to researchers who report particularly severe or unusual bugs. The use-after-free that Pinkie Pie discovered and Google fixed in Chrome 23 met those criteria, as it was an exploit for 64-bit systems, and earned him $7,331.

Here are the flaws fixed in Chrome 23:

[161564] High CVE-2012-5138: Incorrect file path handling. Credit to Google Chrome Security Team (Jüri Aedla).
[$7331] [162835] High CVE-2012-5137: Use-after-free in media source handling. Credit to Pinkie Pie.





« Microsoft Security Essentials fails AV-Test · Two High-Risk Flaws Fixed in Google Chrome 23 · This Boob-Themed Milk Truck Delivers Nourishment »




Comments
comments powered by Disqus

MajorGeeks.Com » News » December 2012 » Two High-Risk Flaws Fixed in Google Chrome 23

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition