자 료 실

서버 / IT Google Chrome 28.0.1500.71 Stable

2013.07.10 01:55

마이크로닉스 조회:4694

https://dl.google.com/chrome/win/28.0.1500.71_chrome_installer.exe


TUESDAY, JULY 9, 2013

Stable Channel Update

The Stable channel has been updated to 28.0.1500.71 for Windows, Macintosh and Chrome Frame platforms.

Security fixes and rewards:


Please see the Chromium security page for more information. (Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.)


This automatic update includes security fixes. We’d like to highlight the following fixes for various reasons (crediting external researchers, issuing rewards, or highlighting particularly interesting issues):


  • [$21,500] A special reward for Andrey Labunets for his combination of CVE-2013-2879 and CVE-2013-2868 along with some (since fixed) server-side bugs.
  • [252216] Low CVE-2013-2867: Block pop-unders in various scenarios.
  • [252062] High CVE-2013-2879: Confusion setting up sign-in and sync. Credit to Andrey Labunets.
  • [252034] Medium CVE-2013-2868: Incorrect sync of NPAPI extension component. Credit to Andrey Labunets.
  • [245153] Medium CVE-2013-2869: Out-of-bounds read in JPEG2000 handling. Credit to Felix Groebert of Google Security Team.
  • [$6267.4] [244746] [242762] Critical CVE-2013-2870: Use-after-free with network sockets. Credit to Collin Payne.
  • [$3133.7] [244260] Medium CVE-2013-2853: Man-in-the-middle attack against HTTP in SSL. Credit to Antoine Delignat-Lavaud and Karthikeyan Bhargavan from Prosecco at INRIA Paris.
  • [$2000] [243991] [243818] High CVE-2013-2871: Use-after-free in input handling. Credit to miaubiz.
  • [Mac only] [242702] Low CVE-2013-2872: Possible lack of entropy in renderers. Credit to Eric Rescorla.
  • [$1000] [241139] High CVE-2013-2873: Use-after-free in resource loading. Credit to miaubiz.
  • [Windows + NVIDIA only] [$500] [237611] Medium CVE-2013-2874: Screen data leak with GL textures. Credit to “danguafer”.
  • [$500] [233848] Medium CVE-2013-2875: Out-of-bounds-read in SVG. Credit to miaubiz.
  • [229504] Medium CVE-2013-2876: Extensions permissions confusion with interstitials. Credit to Dev Akhawe.
  • [229019] Low CVE-2013-2877: Out-of-bounds read in XML parsing. Credit to Aki Helin of OUSPG.
  • [196636] None: Remove the “viewsource” attribute on iframes. Credit to Collin Jackson.
  • [177197] Medium CVE-2013-2878: Out-of-bounds read in text handling. Credit to Atte Kettunen of OUSPG.


In addition, our ongoing internal security work was as usual responsible for a wide range of fixes:
  • [256985] High CVE-2013-2880: Various fixes from internal audits, fuzzing and other initiatives (Chrome 28).


Full details about what changes are in this build are available in the SVN revision log and the Chrome Chrome Blog. Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug.

Anthony Laforge

Google Chrome
번호 제목 글쓴이 조회 추천 등록일
[공지] 저작권 보호 요청 자료 목록 gooddew - - -
[공지] 자료실 이용간 유의사항 gooddew - - -
1641 유틸리티| COMODO Internet Security/Firewall/Antivirus 6.3.294583.... [9] 신지 4478 2 09-25
1640 리눅스 부팅 USB 만들기 Rufus [13] 카리스마조 7014 0 09-25
1639 유틸리티| Microsoft Research Cliplets v1.1.1 [4] KEY 3960 1 09-25
1638 Atlan Update Manager 1.6.6.0 Portable [1] DarknessAn 3734 0 09-25
1637 서버 / IT| Mozilla Firefox 24.0 정식 버전 [6] 브라흐마 4913 2 09-24
1636 미디어| foobar-Portable (최적화) Columns UI 0.3.8.8 적용 [22] ♩♪♬음표 8225 8 09-24
1635 미디어| foobar-Portable (최적화) [7] ♩♪♬음표 5584 2 09-24
1634 미디어| Winamp Pro 5.65 Build 3438 Portable [9] 전저당께요 5422 4 09-23
1633 윈도우 / PE| 업데이트 통합 프로그램 [2] suno 7551 4 09-23
1632 윈도우 / PE| 리눅스 민트 13.04 다운로드 [6] 카리스마조 6177 0 09-23
1631 윈도우 / PE| 윈도우 8.1 토큰백업 [14] gooddew 17195 8 09-22
1630 윈도우 / PE| 탐색기에 북마크를 Direct Folder.. [11] meNyu 5254 4 09-22
1629 윈도우 / PE| 우분투 리눅스 13.04 다운로드 [20] 카리스마조 5968 4 09-22
1628 유틸리티| MediaPreview - 탐색기에서 동영상 썸네일 미리보기 [2] 입교 6930 2 09-22
1627 미디어| Winamp Pro 5.7 Build 3444 Beta portable (수정 22일 pm 4... [12] 전저당께요 4722 3 09-21
1626 유틸리티| Winamp Pro 5.70.3444 [5] X_man 4027 1 09-21
1625 미디어| EZ CD Audio Converter 1.3.1.1 [8] Novastarhe 5646 6 09-21
1624 윈도우 / PE| VMware unlocker 1.20 [2] 블뤠버 8143 1 09-20
1623 유틸리티| AVG 2014 보안백신및 시스템 최적화 [3] X_man 5843 3 09-20
1622 윈도우 / PE| IDA Portable 무설치 버전 [11] 카리스마조 6424 9 09-20
XE1.11.6 Layout1.4.8