Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - Chicks just love a Geek in Uniform.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews




spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. Smart Defrag
2. GS Auto Clicker
3. Macrium Reflect FREE Edition
4. Sergei Strelec's WinPE
5. MusicBee
6. Visual C++ Redistributable Runtimes AIO Repack
7. K-Lite Mega Codec Pack
8. ImgBurn
9. Unlocker
10. Format Factory
More >>

top reads

Star 8 Windows Shortcuts That’ll Make You More Productive and Save You Time

Star Windows 10 Not Dead Yet - You Can Still Get Updates For Free

Star What is a '400 Bad Request - Request Header or Cookie Too Large' Error and How to Fix It

Star How to Fix Windows Install Error 0xC1900101

Star How to Force Enable Windows 10 Extended Security Updates If The Option Is Not Showing

Star Windows 11 25H2 is Out: What’s New and How to Get It Now.

Star Star Trek Fleet Command Promo Codes: Redeem Codes for Free Shards, Blueprints And Resources

Star Boost Your PC Speed with ReadyBoost: How a Thumb Drive Can Enhance Your System's Performance

Star 5 Hidden Windows Tools You’ve Had All Along But Never Use

Star Use the Windows 10 Media Creation Tool Before Support Ends For Windows 10 in 2025


MajorGeeks.Com » News » December 2012 » Two High-Risk Flaws Fixed in Google Chrome 23

Two High-Risk Flaws Fixed in Google Chrome 23


Contributed by: Email on 12/03/2012 03:19 PM [ comments Comments ]


Google has fixed two bugs in its Chrome browser, including a high-severity vulnerability in its media handler that a researcher named Pinkie Pie discovered. The bug, which is different from another use-after-free vulnerability the researcher used in the Pwnium contest at Hack in the Box in October, was serious enough to earn him a bug bounty of more than $7,000.

Google repaired the two high-priority vulnerabilities in Chrome 23, pushing out the new version to users late last week. The company has been very quick to fix security vulnerabilities, especially those that have been made public or come out of contests such as Pwn2Own or the company's own Pwnium, which gives researchers monetary incentives for finding particularly severe flaws in the browser during a set period of time at a conference. The first of the Pwnium contests, which was at CanSecWest in Vancouver earlier this year, produced two sets of bugs from separate researchers who were able to produce full sandbox escapes and compromises of Chrome.

Google patched all of those vulnerabilities within a couple of days of their discovery, and was able to do the same with the other bugs that Pinkie Pie used in the second Pwnium contest at Hack in the Box in October. The company recently said that it would be handing out some larger-than-usual rewards to researchers who report particularly severe or unusual bugs. The use-after-free that Pinkie Pie discovered and Google fixed in Chrome 23 met those criteria, as it was an exploit for 64-bit systems, and earned him $7,331.

Here are the flaws fixed in Chrome 23:

[161564] High CVE-2012-5138: Incorrect file path handling. Credit to Google Chrome Security Team (Jüri Aedla).
[$7331] [162835] High CVE-2012-5137: Use-after-free in media source handling. Credit to Pinkie Pie.





« Microsoft Security Essentials fails AV-Test · Two High-Risk Flaws Fixed in Google Chrome 23 · This Boob-Themed Milk Truck Delivers Nourishment »




Comments
comments powered by Disqus

MajorGeeks.Com » News » December 2012 » Two High-Risk Flaws Fixed in Google Chrome 23

© 2000-2025 MajorGeeks.com
Powered by Contentteller® Business Edition