자 료 실

서버 / IT Google Chrome 28.0.1500.71 Stable

2013.07.10 01:55

마이크로닉스 조회:4696

https://dl.google.com/chrome/win/28.0.1500.71_chrome_installer.exe


TUESDAY, JULY 9, 2013

Stable Channel Update

The Stable channel has been updated to 28.0.1500.71 for Windows, Macintosh and Chrome Frame platforms.

Security fixes and rewards:


Please see the Chromium security page for more information. (Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.)


This automatic update includes security fixes. We’d like to highlight the following fixes for various reasons (crediting external researchers, issuing rewards, or highlighting particularly interesting issues):


  • [$21,500] A special reward for Andrey Labunets for his combination of CVE-2013-2879 and CVE-2013-2868 along with some (since fixed) server-side bugs.
  • [252216] Low CVE-2013-2867: Block pop-unders in various scenarios.
  • [252062] High CVE-2013-2879: Confusion setting up sign-in and sync. Credit to Andrey Labunets.
  • [252034] Medium CVE-2013-2868: Incorrect sync of NPAPI extension component. Credit to Andrey Labunets.
  • [245153] Medium CVE-2013-2869: Out-of-bounds read in JPEG2000 handling. Credit to Felix Groebert of Google Security Team.
  • [$6267.4] [244746] [242762] Critical CVE-2013-2870: Use-after-free with network sockets. Credit to Collin Payne.
  • [$3133.7] [244260] Medium CVE-2013-2853: Man-in-the-middle attack against HTTP in SSL. Credit to Antoine Delignat-Lavaud and Karthikeyan Bhargavan from Prosecco at INRIA Paris.
  • [$2000] [243991] [243818] High CVE-2013-2871: Use-after-free in input handling. Credit to miaubiz.
  • [Mac only] [242702] Low CVE-2013-2872: Possible lack of entropy in renderers. Credit to Eric Rescorla.
  • [$1000] [241139] High CVE-2013-2873: Use-after-free in resource loading. Credit to miaubiz.
  • [Windows + NVIDIA only] [$500] [237611] Medium CVE-2013-2874: Screen data leak with GL textures. Credit to “danguafer”.
  • [$500] [233848] Medium CVE-2013-2875: Out-of-bounds-read in SVG. Credit to miaubiz.
  • [229504] Medium CVE-2013-2876: Extensions permissions confusion with interstitials. Credit to Dev Akhawe.
  • [229019] Low CVE-2013-2877: Out-of-bounds read in XML parsing. Credit to Aki Helin of OUSPG.
  • [196636] None: Remove the “viewsource” attribute on iframes. Credit to Collin Jackson.
  • [177197] Medium CVE-2013-2878: Out-of-bounds read in text handling. Credit to Atte Kettunen of OUSPG.


In addition, our ongoing internal security work was as usual responsible for a wide range of fixes:
  • [256985] High CVE-2013-2880: Various fixes from internal audits, fuzzing and other initiatives (Chrome 28).


Full details about what changes are in this build are available in the SVN revision log and the Chrome Chrome Blog. Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug.

Anthony Laforge

Google Chrome
번호 제목 글쓴이 조회 추천 등록일
[공지] 저작권 보호 요청 자료 목록 gooddew - - -
[공지] 자료실 이용간 유의사항 gooddew - - -
1467 유틸리티| Wise Data Recovery v3.22 (삭제된 파일 복구) 마니아 5038 1 06-20
1466 유틸리티| Wise Disk Cleaner v7.81 (하드디스크 청소) 마니아 3953 0 06-20
1465 유틸리티| 유투브 속도 패치 마니아 3865 0 06-20
1464 유틸리티| Wise Registry Cleaner 7.73 [무설치, 레지스트리 검사/수정] 마니아 3578 1 06-20
1463 윈도우 / PE| 복구 불가능 삭제툴 [3] 마니아 5422 0 06-20
1462 유틸리티| 3DP Chip v13.05 Portable [5] 마니아 3832 0 06-20
1461 유틸리티| Ultra RAMDisk 0.77 마니아 4134 1 06-20
1460 유틸리티| 디스크 조각모음 툴 [1] 마니아 4188 0 06-20
1459 유틸리티| Microsoft Fixit 마니아 4639 0 06-20
1458 서버 / IT| 카카오톡 PC 버전 [9] 마니아 8649 1 06-20
1457 서버 / IT| firefox night biuld [1] Lr라 4446 0 06-20
1456 미디어| UE Sounder - 사진 수정 [7] Lr라 4297 1 06-20
1455 유틸리티| Java Runtime Environment 7.0 Update 25 Novastarhe 3407 0 06-19
1454 유틸리티| A Bootable USB 유틸 [6] 마니아 5096 2 06-19
1453 유틸리티| USB Image 제작툴 [3] 마니아 4576 1 06-19
1452 유틸리티| 아래에 이어 바탕화면 아이콘위치 고정 유틸들..... 골드캐쉬 5284 0 06-19
1451 유틸리티| 바탕화면 아이콘고정 DesktopOK 3.56 으로 업되었네요 [4] 골드캐쉬 4043 2 06-19
1450 윈도우 / PE| 웹사이트 즐겨찾기 아이콘 갱신하기 [2] 마니아 3642 2 06-18
1449 Anvi Ultimate Defrag Pro 1.0 Portable [1] DarknessAn 3670 2 06-18
1448 유틸리티| Everything 1.3.3.653b Beta 업데이트 [14] 히릿 5130 5 06-17
XE1.11.6 Layout1.4.8