자유 게시판

크롬 37 업데이트~

2014.08.27 10:20

마스크 조회:1068

아무래도 가장 큰 변화는

GDI 폰트를 버리고 다이렉트 라이트로 폰트를 처리하는 것이 큰 변화네요.


폰트 처리 변경에 대한 크롬 뉴스

https://www.itworld.co.kr/news/88587


버그 발견하면 돈주는건 여전히 진행중

Stable Channel Update

The Chrome team is delighted to announce the promotion of Chrome 37 to the stable channel for Windows, Mac and Linux. Chrome 37.0.2062.94 contains a number of fixes and improvements, including:

 - DirectWrite support on Windows for improved font rendering
 - A number of new apps/extension APIs
 - Lots of under the hood changes for stability and performance

A full list of changes is available in the log.

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

This update includes 50 security fixes. Below, we highlight fixes that were either contributed by external researchers or particularly interesting. Please see the Chromium security page for more information.

[$30000][386988] Critical CVE-2014-3176, CVE-2014-3177: A special reward to lokihardt@asrt for a combination of bugs in V8, IPC, sync, and extensions that can lead to remote code execution outside of the sandbox.
[$2000][369860] High CVE-2014-3168: Use-after-free in SVG. Credit to cloudfuzzer.
[$2000][387389] High CVE-2014-3169: Use-after-free in DOM. Credit to Andrzej Dyjak.
[$1000][390624] High CVE-2014-3170: Extension permission dialog spoofing. Credit to Rob Wu.
[$4000][390928] High CVE-2014-3171: Use-after-free in bindings. Credit to cloudfuzzer.
[$1500][367567] Medium CVE-2014-3172: Issue related to extension debugging. Credit to Eli Grey.
[$2000][376951] Medium CVE-2014-3173: Uninitialized memory read in WebGL. Credit to jmuizelaar.
[$500][389219] Medium CVE-2014-3174: Uninitialized memory read in Web Audio. Credit to Atte Kettunen from OUSPG.

We would also like to thank Collin Payne, Christoph Diehl, Sebastian Mauer, Atte Kettunen, and cloudfuzzer for working with us during the development cycle to prevent security bugs from ever reaching the stable channel. $8000 in additional rewards were issued.

As usual, our ongoing internal security work responsible for a wide range of fixes:
[406143] CVE-2014-3175: Various fixes from internal audits, fuzzing and other initiatives (Chrome 37).

Many of the above bugs were detected using AddressSanitizer.

Interested in switching release channels? Find out how. If you find a new issue, please let us know by filing a bug.
번호 제목 글쓴이 조회 등록일
[공지] 자유 게시판 이용간 유의사항 (정치, 종교, 시사 게시물 자제) [1] gooddew - -
23397 sk로 번이하면서 kt 포인트 다 털었어요 ㅎㅎ [3] 오호잉 1015 09-11
23396 귀태족속 들의 속보이고 뻔한 ~~~ 딴지걸기!!! [12] 삐리리 1038 09-11
23395 월급 외에 이자·연금 등 대부분 소득에 건보료 매긴다 [3] 고양이2 1106 09-11
23394 흡연율 핑계로 곳간 채우기... [5] 고양이2 993 09-11
23393 귀태 족속들~~~~ [4] 삐리리 836 09-11
23392 업데이트 안하고 계속 그냥 보고 있는데요 [5] 마스크 1304 09-11
23391 시발 담배값 올리면 수입산도 동반 올라가나요?? [27] ㄷㄱ 1992 09-11
23390 2014년 afc u-16챔피언십, 한국 vs 태국 [3] 고양이2 914 09-10
23389 정말자유계시판 맞내요 [4] 가온누리 982 09-10
23388 티카페에 자료를 올리는 분 자제 좀 합시다. [9] 한걸음 1856 09-10
23387 전라북도 식도 추석당일 보름달의 모습입니다 [11] 꼬마 1233 09-10
23386 Apple 컨퍼런스 시작 asklee 969 09-10
23385 일본 vs 배네수엘라 하이라이트 [4] 고양이2 1143 09-10
23384 구함 - Google Chrome 37.0.2062.94 Stable 64bit 포터블 [17] 박삿갓 1979 09-09
23383 닭꼬치 [1] 고양이2 1034 09-09
23382 PE 에서 '사일런트힐 - 제로' 를 해보고 있습니다. [1] bleach 3085 09-09
23381 윈포는 누구의 것 입니까?.... [7] 오늘을사는 1328 09-09
23380 궁금한게 있습니다. [6] ccvc12 1154 09-09
23379 담뱃값 [12] 고양이2 1362 09-08
23378 음. 또 블루스크린 뜹니다. [4] suk 1646 09-08
XE1.11.6 Layout1.4.8