View Full Version : Google Chrome updates
AplusWebMaster
2012-03-22, 12:17
FYI...
Chrome v17.0.963.83 released
- https://secunia.com/advisories/48512/
Release Date: 2012-03-22
Criticality level: Highly critical
Impact: Security Bypass, System access
Where: From remote
CVE Reference(s): CVE-2011-3045, CVE-2011-3050, CVE-2011-3051, CVE-2011-3052, CVE-2011-3053, CVE-2011-3054, CVE-2011-3055, CVE-2011-3056, CVE-2011-3057
Solution: Update to version 17.0.963.83.
Original Advisory:
http://googlechromereleases.blogspot.com/2012/03/stable-channel-update_21.html
Related: https://secunia.com/advisories/48485/
"... update for libpng..."
- http://www.securitytracker.com/id/1026841
Mar 23 2012
:fear::fear:
AplusWebMaster
2012-03-29, 11:07
FYI...
Chrome v18.0.1025.142 released
- https://secunia.com/advisories/48618/
Release Date: 2012-03-29
Criticality level: Highly critical
Impact: Unknown, Cross Site Scripting, Spoofing, System access
Where: From remote...
CVE Reference(s): CVE-2011-3057, CVE-2011-3058, CVE-2011-3059, CVE-2011-3060, CVE-2011-3061, CVE-2011-3062, CVE-2011-3063, CVE-2011-3064, CVE-2011-3065, CVE-2012-0772, CVE-2012-0773
Solution: Upgrade to version 18.0.1025.142.
Original Advisory:
http://googlechromereleases.blogspot.com/2012/03/stable-channel-release-and-beta-channel.html
"... This version also contains the new Adobe Flash..."
:fear::fear:
AplusWebMaster
2012-04-06, 13:51
FYI...
Chrome v18.0.1025.151 released
- https://secunia.com/advisories/48732/
Release Date: 2012-04-06
Criticality level: Highly critical
Impact: Unknown, Security Bypass, System access
Where: From remote...
Solution: Update to version 18.0.1025.151.
Original Advisory:
http://googlechromereleases.blogspot.com/2012/04/stable-and-beta-channel-updates.html
- http://www.securitytracker.com/id/1026892
Date: Apr 5 2012
CVE Reference: CVE-2011-3066, CVE-2011-3067, CVE-2011-3068, CVE-2011-3069, CVE-2011-3070, CVE-2011-3071, CVE-2011-3072, CVE-2011-3073, CVE-2011-3074, CVE-2011-3075, CVE-2011-3076, CVE-2011-3077
Impact: Disclosure of user information, Execution of arbitrary code via network, Modification of user information, User access via network
Fix Available: Yes Vendor Confirmed: Yes
Version(s): prior to 18.0.1025.151...
:fear:
AplusWebMaster
2012-04-11, 00:09
FYI...
Chrome v18.0.1025.152 released
- http://googlechromereleases.blogspot.com/search/label/Stable%20updates
April 9, 2012 - "The Chrome Stable channel has been updated to 18.0.1025.152 on Windows. This release fixes issues with SSL (Issue: 118706). Please note this might reintroduce Issue: 117371 and we are actively working on a fix for it..."
:fear::fear:
AplusWebMaster
2012-04-13, 14:04
FYI...
Chrome v18.0.1025.162 released
- http://googlechromereleases.blogspot.com/search/label/Stable%20updates
April 12, 2012 - "The Chrome Stable channel has been updated to 18.0.1025.162 on on Windows, Mac, Linux and Chrome Frame. This release fixes issues including:
Windows:
• Facebook page hangs after a while (Issue: 121141)
• black screen on Hybrid Graphics system with GPU accelerated compositing enabled (Issue: 117371)
Mac:
• HTML5 audio doesn't work on some Mac computers (Issue: 109441)..."
:fear::fear:
AplusWebMaster
2012-05-01, 15:10
FYI...
Chrome v18.0.1025.168 released
- https://secunia.com/advisories/48992/
Release Date: 2012-05-01
Criticality level: Highly critical
Impact: Unknown, System access
Where: From remote
CVE Reference(s):
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3078 - 10.0 (HIGH)
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3079 - 10.0 (HIGH)
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3080 - 7.5 (HIGH)
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3081 - 7.5 (HIGH)
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1521 - 10.0 (HIGH)
... vulnerabilities are reported in versions prior to 18.0.1025.168.
Solution: Update to version 18.0.1025.168...
> http://googlechromereleases.blogspot.com/search/label/Stable%20updates
April 30, 2012
:fear::spider:
AplusWebMaster
2012-05-16, 16:13
FYI...
Chrome v19.0.1084.46 released
- https://secunia.com/advisories/49194/
Release Date: 2012-05-16
Criticality level: Highly critical
... vulnerabilities are reported in versions prior to 19.0.1084.46.
Solution: Upgrade to version 19.0.1084.46.
Original Advisory:
http://googlechromereleases.blogspot.com/2012/05/stable-channel-update.html
- http://www.securitytracker.com/id/1027067
CVE Reference:
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3083 - 5.0
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3084 - 7.5 (HIGH)
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3085 - 5.0
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3086 - 10.0 (HIGH)
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3087 - 10.0 (HIGH)
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3088 - 5.0
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3089 - 10.0 (HIGH)
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3090 - 7.6 (HIGH)
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3091 - 7.5 (HIGH)
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3092 - 7.5 (HIGH)
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3093 - 5.0
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3094 - 5.0
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3095 - 7.5 (HIGH)
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3096 - 7.5 (HIGH)
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3097 - 7.5 (HIGH)
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3098 - 7.2 (HIGH)
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3099 - 7.5 (HIGH)
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3100 - 5.0
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3101 - 10.0 (HIGH)
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3102 - 7.5 (HIGH)
May 16 2012
Impact: Execution of arbitrary code via network, User access via network
A remote user can create content that, when loaded by the target user, will execute arbitrary code on the target user's system.
Version(s): prior to 19 ...
:fear::fear:
AplusWebMaster
2012-05-24, 15:45
FYI...
Chrome v19.0.1084.52 released
- https://secunia.com/advisories/49277/
Release Date: 2012-05-24
Criticality level: Highly critical
Impact: Unknown, System access
Where: From remote
CVE Reference(s): CVE-2011-3103, CVE-2011-3104, CVE-2011-3105, CVE-2011-3106, CVE-2011-3107, CVE-2011-3108, CVE-2011-3109, CVE-2011-3110, CVE-2011-3111, CVE-2011-3112, CVE-2011-3113, CVE-2011-3114, CVE-2011-3115
... vulnerabilities are reported in versions prior to 19.0.1084.52.
Solution: Update to version 19.0.1084.52.
Original Advisory:
http://googlechromereleases.blogspot.com/2012/05/stable-channel-update_23.html
- http://www.securitytracker.com/id/1027098
May 24 2012
Impact: Execution of arbitrary code via network, User access via network
Version(s): prior to 19.0.1084.52 ...
:fear::fear:
AplusWebMaster
2012-06-11, 14:18
FYI...
Chrome v19.0.1084.56 released
- https://secunia.com/advisories/49503/
Release Date: 2012-06-11
Criticality level: Highly critical
Impact: Security Bypass, System access
Where: From remote
... more information: https://secunia.com/SA49388/
Solution: Update to version 19.0.1084.56.
Original Advisory:
http://googlechromereleases.blogspot.com/2012/06/stable-channel-update_08.html
:fear:
AplusWebMaster
2012-06-27, 12:38
FYI...
Chrome v20.0.1132.43 released
- https://secunia.com/advisories/49724/
Release Date: 2012-06-27
Criticality level: Highly critical
Impact: Unknown, Security Bypass, Exposure of sensitive information, System access
Where: From remote ...
CVE Reference(s): CVE-2012-2764, CVE-2012-2815, CVE-2012-2816, CVE-2012-2817, CVE-2012-2818, CVE-2012-2819, CVE-2012-2820, CVE-2012-2821, CVE-2012-2822, CVE-2012-2823, CVE-2012-2824, CVE-2012-2826, CVE-2012-2827, CVE-2012-2828, CVE-2012-2829, CVE-2012-2830, CVE-2012-2831, CVE-2012-2832, CVE-2012-2833, CVE-2012-2834
Solution: Upgrade to version 20.0.1132.43.
Original Advisory:
- http://googlechromereleases.blogspot.com/2012/06/stable-channel-update_26.html
:fear::fear:
AplusWebMaster
2012-07-11, 19:14
FYI...
Chrome v20.0.1132.57 released
- http://googlechromereleases.blogspot.com/search/label/Stable%20updates
July 11, 2012 - "The Stable channel has been updated to 20.0.1132.57 for Windows, Mac, Linux, and Chrome Frame. Along with below mentioned security fixes, this build contains an update to Flash player, v8 (3.10.8.20) and couple of stability/bug fixes...
High CVE-2012-2842: Use-after-free in counter handling...
High CVE-2012-2843: Use-after-free in layout height tracking...
High CVE-2012-2844: Bad object access with JavaScript in PDF..."
- https://secunia.com/advisories/49906/
Release Date: 2012-07-12
Criticality level: Highly critical
Impact: System access
Where: From remote
Solution: Update to version 20.0.1132.57.
Original Advisory: Google:
http://googlechromereleases.blogspot.com/2012/07/stable-channel-update.html
:fear::fear:
AplusWebMaster
2012-08-01, 15:28
FYI...
Chrome v21.0.1180.60 released
- https://secunia.com/advisories/50105/
Release Date: 2012-08-01
Criticality level: Highly critical
Impact: Security Bypass, System access
Where: From remote...
CVE Reference(s): CVE-2012-2846, CVE-2012-2847, CVE-2012-2848, CVE-2012-2849, CVE-2012-2850, CVE-2012-2851, CVE-2012-2852, CVE-2012-2853, CVE-2012-2854, CVE-2012-2855, CVE-2012-2856, CVE-2012-2857, CVE-2012-2858, CVE-2012-2859, CVE-2012-2860
Original Advisory:
http://googlechromereleases.blogspot.com/2012/07/stable-channel-release.html
"... release of Chrome 21 to the Stable Channel. 21.0.1180.57 for Mac and Linux. 21.0.1180.60 for Windows and Chrome Frame..."
- http://h-online.com/-1657169
1 August 2012
:fear::spider:
AplusWebMaster
2012-08-09, 15:12
FYI...
Chrome v21.0.1180.75 released
- https://secunia.com/advisories/50222/
Release Date: 2012-08-09
Criticality level: Highly critical
Impact: System access
Where: From remote
CVE Reference(s): CVE-2012-2862, CVE-2012-2863
... vulnerabilities are reported in versions prior to 21.0.1180.75.
Solution: Update to version 21.0.1180.75.
Original Advisory:
http://googlechromereleases.blogspot.com/2012/08/stable-channel-update.html
Security fixes...
• [136643] [137721] [137957] High CVE-2012-2862: Use-after-free in PDF viewer...
• [136968] [137361] High CVE-2012-2863: Out-of-bounds writes in PDF viewer...
:fear::fear:
AplusWebMaster
2012-08-15, 14:16
FYI...
Chrome v21.0.1180.79 released
- https://secunia.com/advisories/50286/
Release Date: 2012-08-14
Criticality level: Highly critical
Impact: System access
Where: From remote...
CVE Reference: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1535
... vulnerability is caused due to the application bundling a vulnerable version of Adobe Flash Player.
For more information: https://secunia.com/SA50285/
Solution: Update to version 21.0.1180.79 for Mac, Linux, Windows, and Chrome Frame.
Original Advisory: Google:
http://googlechromereleases.blogspot.dk/2012/08/stable-channel-update_14.html
August 14, 2012 - "The Stable channel has been updated to 21.0.1180.79 for Mac, Linux, Windows and Chrome Frame. This build fixes a security issue with Adobe Flash..."
>> http://forums.spybot.info/showpost.php?p=429696&postcount=80
:fear:
AplusWebMaster
2012-08-22, 14:31
FYI...
Chrome v21.0.1180.83 released
- https://secunia.com/advisories/50356/
Release Date: 2012-08-22
Criticality level: Highly critical
Impact: Exposure of sensitive information, System access
Where: From remote
... vulnerabilities are caused due to the application bundling a vulnerable version of Adobe Flash Player.
For more information: https://secunia.com/SA50354/
Solution: Update to a fixed version...
Original Advisory:
http://googlechromereleases.blogspot.dk/2012/08/stable-channel-update_21.html
August 21, 2012 - "The Stable channel has been updated to 21.0.1180.81 for Linux, 21.0.1180.83 for Windows and Chrome Frame and both Beta and Stable channels have been updated to 21.0.1180.82 for Mac...
These builds also have a new version of Flash with security and other fixes..."
:fear:
AplusWebMaster
2012-08-31, 13:42
FYI...
Chrome v21.0.1180.89 released
- https://secunia.com/advisories/50447/
Release Date: 2012-08-31
Criticality level: Highly critical
Impact: Unknown, Cross Site Scripting, System access
Where: From remote...
CVE Reference(s): CVE-2012-2865, CVE-2012-2866, CVE-2012-2867, CVE-2012-2868, CVE-2012-2869, CVE-2012-2870, CVE-2012-2871, CVE-2012-2872
... vulnerabilities are reported in versions prior to 21.0.1180.89.
Solution: Update to version 21.0.1180.89.
Original Advisory:
http://googlechromereleases.blogspot.com/2012/08/stable-channel-update_30.html
___
- http://h-online.com/-1696236
31 August 2012
:fear:
AplusWebMaster
2012-09-26, 13:04
FYI...
Chrome v22.0.1229.79 released
- https://secunia.com/advisories/50759/
Release Date: 2012-09-26
Criticality level: Highly critical
Impact: Unknown, Security Bypass, Cross Site Scripting, System access
Where: From remote ...
CVE Reference(s): CVE-2012-2874, CVE-2012-2875, CVE-2012-2876, CVE-2012-2877, CVE-2012-2878, CVE-2012-2879, CVE-2012-2880, CVE-2012-2881, CVE-2012-2882, CVE-2012-2883, CVE-2012-2884, CVE-2012-2885, CVE-2012-2886, CVE-2012-2887, CVE-2012-2888, CVE-2012-2889, CVE-2012-2890, CVE-2012-2891, CVE-2012-2892, CVE-2012-2893, CVE-2012-2894, CVE-2012-2895, CVE-2012-2896
Solution: Upgrade to version 22.0.1229.79.
Original Advisory: Google:
http://googlechromereleases.blogspot.dk/2012/09/stable-channel-update_25.html
___
Security fixes dominate Chrome 22
- http://h-online.com/-1717660
26 Sep 2012 - "... closes more than 40 security holes, of which one is considered to be critical and 19 are rated as 'high severity'..."
:fear:
AplusWebMaster
2012-10-09, 13:50
FYI...
Chrome v22.0.1229.92 released
- https://secunia.com/advisories/50872/
Release Date: 2012-10-09
Criticality level: Highly critical
Impact: System access
Where: From remote
Solution: Update to version 22.0.1229.92.
Original Advisory: http://googlechromereleases.blogspot.dk/2012/10/stable-channel-update.html
October 8, 2012 - "... This update contains a number of stability fixes, including an issue with multiple profiles on Mac OS X 10.8.2... These builds also have a new version of Flash with security and other fixes. More information can be found here*..."
* http://helpx.adobe.com/flash-player/release-note/fp_114_air_34_release_notes.html#fixed_issues
- http://www.securitytracker.com/id/1027617
CVE Reference: CVE-2012-2900, CVE-2012-5108, CVE-2012-5109, CVE-2012-5110, CVE-2012-5111
Oct 8 2012
Version(s): prior to 22.0.1229.92
Impact: A remote user can create content that, when loaded by the target user, will execute arbitrary code on the target user's system...
Solution: The vendor has issued a fix (22.0.1229.92).
:fear:
AplusWebMaster
2012-10-11, 14:07
FYI...
Chrome v22.0.1229.94 released
- https://secunia.com/advisories/50954/
Release Date: 2012-10-11
Criticality level: Highly critical
Impact: Security Bypass, System access
Where: From remote
CVE Reference: CVE-2012-5112
Solution: Update to version 22.0.1229.94.
Original Advisory: Google:
- http://googlechromereleases.blogspot.com/search/label/Stable%20updates
Oct 10, 2012
- http://www.securitytracker.com/id/1027644
CVE Reference: CVE-2012-5112
Oct 11 2012
Impact: A remote user can create content that, when loaded by the target user, will execute arbitrary code on the target user's system.
Solution: The vendor has issued a fix (22.0.1229.94).
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-5112 - 10.0 (HIGH)
- http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-5376 - 10.0 (HIGH)
:fear:
AplusWebMaster
2012-11-06, 21:36
FYI...
Chrome v23.0.1271.64 released
- http://googlechromereleases.blogspot.com/search/label/Stable%20updates
Nov 6, 2012 - "... 23.0.1271.64 for Windows, Mac, Linux, and Chrome Frame. Chrome 23 contains a number of new features including GPU accelerated video decoding on Windows and easier website permissions... referenced bugs may be kept private until a majority of our users are up to date with the fix... This version also has a new Adobe Flash..."
___
- https://secunia.com/advisories/51210/
Release Date: 2012-11-07
Criticality level: Highly critical
Impact: Security Bypass, System access
Where: From remote
CVE Reference(s): CVE-2012-5115, CVE-2012-5116, CVE-2012-5117, CVE-2012-5118, CVE-2012-5119, CVE-2012-5120, CVE-2012-5121, CVE-2012-5122, CVE-2012-5123, CVE-2012-5124, CVE-2012-5125, CVE-2012-5126, CVE-2012-5127, CVE-2012-5128, CVE-2012-5274, CVE-2012-5275, CVE-2012-5276, CVE-2012-5277, CVE-2012-5278, CVE-2012-5279, CVE-2012-5280
Solution: Upgrade to version 23.0.1271.64.
Original Advisory: Google:
http://googlechromereleases.blogspot.dk/2012/11/stable-channel-release-and-beta-channel.html
:fear::fear:
AplusWebMaster
2012-11-27, 15:10
FYI...
Chrome v23.0.1271.91 released
- https://secunia.com/advisories/51437/
Release Date: 2012-11-27
Criticality level: Highly critical
Impact: Unknown, System access
Where: From remote
CVE Reference(s): CVE-2012-5130, CVE-2012-5131, CVE-2012-5132, CVE-2012-5133, CVE-2012-5134,
CVE-2012-5135, CVE-2012-5136
... more information see vulnerability #2: https://secunia.com/SA48000/
... vulnerabilities are reported in versions prior to 23.0.1271.91.
Solution: Update to version 23.0.1271.91.
Original Advisory: http://googlechromereleases.blogspot.dk/2012/11/stable-channel-update.html
- http://www.securitytracker.com/id/1027815
CVE Reference: CVE-2012-5130, CVE-2012-5131, CVE-2012-5132, CVE-2012-5133, CVE-2012-5134, CVE-2012-5135, CVE-2012-5136
Nov 27 2012
Impact: Execution of arbitrary code via network, User access via network
Fix Available: Yes Vendor Confirmed: Yes
Version(s): prior to 23.0.1271.91 ...
:fear:
AplusWebMaster
2012-11-30, 14:36
FYI...
Chrome v23.0.1271.95 released
- https://secunia.com/advisories/51447/
Release Date: 2012-11-30
Criticality level: Highly critical
Impact: Unknown, System access
Where: From remote
CVE Reference(s): CVE-2012-5137, CVE-2012-5138
... vulnerabilities are reported in versions prior to 23.0.1271.95.
Solution: Update to version 23.0.1271.95.
Original Advisory:
http://googlechromereleases.blogspot.dk/2012/11/stable-channel-update_29.html
:fear:
AplusWebMaster
2012-12-12, 12:14
FYI...
Chrome v23.0.1271.97 released
- https://secunia.com/advisories/51549/
Release Date: 2012-12-12
Criticality level: Highly critical
Impact: Unknown, System access
Where: From remote
CVE Reference(s): CVE-2012-5139, CVE-2012-5140, CVE-2012-5141, CVE-2012-5142, CVE-2012-5143, CVE-2012-5144, CVE-2012-5676, CVE-2012-5677, CVE-2012-5678
For more information: https://secunia.com/SA51560/
... vulnerabilities are reported in versions prior to 23.0.1271.97.
Solution: Update to version 23.0.1271.97.
Original Advisory: Google:
http://googlechromereleases.blogspot.dk/2012/12/stable-channel-update.html
___
- http://h-online.com/-1774354
24 Dec 2012
:fear:
AplusWebMaster
2013-01-11, 08:08
FYI...
Chrome v24.0.1312.52 released
- https://secunia.com/advisories/51825/
Release Date: 2013-01-11
Criticality level: Highly critical
Impact: Unknown, Security Bypass, System access
Where: From remote
CVE Reference(s): CVE-2012-5145, CVE-2012-5146, CVE-2012-5147, CVE-2012-5148, CVE-2012-5149, CVE-2012-5150, CVE-2012-5151, CVE-2012-5152, CVE-2012-5153, CVE-2012-5154, CVE-2012-5155, CVE-2012-5156, CVE-2012-5157, CVE-2013-0630, CVE-2013-0828, CVE-2013-0829, CVE-2013-0830, CVE-2013-0831, CVE-2013-0832, CVE-2013-0833, CVE-2013-0834, CVE-2013-0835, CVE-2013-0836, CVE-2013-0837, CVE-2013-0838
... vulnerabilities are reported in versions prior to 24.0.1312.52.
Solution: Upgrade to version 24.0.1312.52.
Original Advisory:
- http://googlechromereleases.blogspot.com/2013/01/stable-channel-update.html
Jan 10, 2013 - "... Chrome 24.0.1312.52 has been updated for Windows, Mac, Linux, and Chrome Frame... This release also contains an update to Flash (11.5.31.137) as well as improvements in speed and stability..."
- http://h-online.com/-1781648
11 Jan 2013
:fear::fear:
AplusWebMaster
2013-01-23, 14:45
FYI...
Chrome v24.0.1312.56 released
- https://secunia.com/advisories/51935/
Release Date: 2013-01-23
Criticality level: Highly critical
Impact: Unknown, System access
Where: From remote
CVE Reference(s): CVE-2013-0839, CVE-2013-0840, CVE-2013-0841, CVE-2013-0842, CVE-2013-0843
... vulnerabilities are reported in versions prior to 24.0.1312.56.
Solution: Update to version 24.0.1312.56.
Original Advisory:
http://googlechromereleases.blogspot.com/2013/01/stable-channel-update_22.html
___
- http://www.theregister.co.uk/2013/01/22/pwn2own_web_plugin_prize/
22 Jan 2013
- http://h-online.com/-1791381
25 Jan 2013
:fear::fear:
AplusWebMaster
2013-02-12, 21:52
FYI...
Chrome v24.0.1312.70 released
- https://secunia.com/advisories/52163/
Release Date: 2013-02-12
Criticality level: Highly critical
Impact: Exposure of sensitive information, System access
Where: From remote...
For more information: https://secunia.com/SA52166/
Solution: Update to version 24.0.1312.70.
Original Advisory:
- http://googlechromereleases.blogspot.com/2013/02/stable-channel-update_12.html
:fear:
AplusWebMaster
2013-02-22, 11:32
FYI...
Chrome v25.0.1364.97 released
- https://secunia.com/advisories/52320/
Release Date: 2013-02-22
Criticality level: Highly critical
Impact: Unknown, Security Bypass, System access
Where: From remote
CVE Reference(s): CVE-2013-0879, CVE-2013-0880, CVE-2013-0881, CVE-2013-0882, CVE-2013-0883, CVE-2013-0884, CVE-2013-0885, CVE-2013-0886, CVE-2013-0887, CVE-2013-0888, CVE-2013-0889, CVE-2013-0890, CVE-2013-0891, CVE-2013-0892, CVE-2013-0893, CVE-2013-0894, CVE-2013-0895, CVE-2013-0896, CVE-2013-0897, CVE-2013-0898, CVE-2013-0899, CVE-2013-0900
... vulnerabilities are reported in versions prior to 25.0.1364.97 for Windows and Linux and prior to 25.0.1364.99 for Mac.
Solution: Upgrade to version 25.0.1364.97 for Windows and Linux and 25.0.1364.99 for Mac.
Original Advisory:
- http://googlechromereleases.blogspot.com.au/2013/02/stable-channel-update_21.html
Feb 21, 2013 - "... Chrome 25.0.1364.97 for Windows and Linux, and 25.0.1364.99 for Mac contain a number of new items including:
- Improvements in managing and securing your extensions
- Better support for HTML5 time/date inputs
- JavaScript Web Speech API support
- Better WebGL error handling
- And lots of other features for developers
Security fixes... We’ve also resolved a high severity security issue by disabling MathML in this release. The WebKit MathML implementation isn’t quite ready for prime time yet but we are excited to enable it again in a future release once the security issues have been addressed. Many... bugs were detected using AddressSanitizer..."
:fear:
AplusWebMaster
2013-03-04, 23:59
FYI...
Chrome v25.0.1364.152 released
- http://googlechromereleases.blogspot.com/2013/03/stable-channel-update_4.html
March 4, 2013 - "The Stable channel has been updated to 25.0.1364.152 for Windows and Linux. Note: these release notes also apply to the same version for Mac that was released last Friday. This release contains security and stability improvements along with a number of bug fixes... the referenced bugs may be kept private until a majority of our users are up to date with the fix..."
- https://secunia.com/advisories/52454/
Release Date: 2013-03-05
Criticality level: Highly critical
Impact: Unknown, System access
Where: From remote ...
CVE Reference(s): CVE-2013-0902, CVE-2013-0903, CVE-2013-0904, CVE-2013-0905, CVE-2013-0906, CVE-2013-0907, CVE-2013-0908, CVE-2013-0909, CVE-2013-0910, CVE-2013-0911
... vulnerabilities are reported in versions prior to 25.0.1364.152.
Solution: Update to version 25.0.1364.152.
:fear::fear:
AplusWebMaster
2013-03-08, 14:00
FYI...
Chrome v25.0.1364.160 released
- https://secunia.com/advisories/52534/
Release Date: 2013-03-08
Criticality level: Highly critical
Impact: System access
Where: From remote
CVE Reference: CVE-2013-0912
... vulnerability is reported in versions prior to 25.0.1364.160.
Solution: Update to version 25.0.1364.160.
Original Advisory: Chrome:
http://googlechromereleases.blogspot.dk/2013/03/stable-channel-update_7.html
MWR InfoSecurity:
http://labs.mwrinfosecurity.com/blog/2013/03/06/pwn2own-at-cansecwest-2013/
:fear:
AplusWebMaster
2013-03-13, 13:06
FYI...
Chrome v25.0.1364.172 released
- https://secunia.com/advisories/52591/
Release Date: 2013-03-12
Criticality level: Highly critical
Impact: System access
Where: From remote
CVE Reference(s): CVE-2013-0646, CVE-2013-0650, CVE-2013-1371, CVE-2013-1375
For more information: https://secunia.com/SA52590/
... vulnerabilities are reported in versions prior to 25.0.1364.172.
Solution: Update to version 25.0.1364.172.
Original Advisory:
http://googlechromereleases.blogspot.dk/2013/03/stable-channel-update_12.html
AplusWebMaster
2013-03-20, 16:25
FYI...
Chrome v25.0.1364.173 released
- http://www.securitytracker.com/id/1028320
CVE Reference:
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-0913 - 7.2 (HIGH)
- https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-0915 - 10.0 (HIGH)
Mar 19 2013
Impact: Execution of arbitrary code via network, User access via network
Fix Available: Yes Vendor Confirmed: Yes
Version(s): prior to 25.0.1364.173...
Impact: A remote user can create content that, when loaded by the target user, will execute arbitrary code on the target user's system.
Solution: The vendor has issued a fix (25.0.1364.173)...
- http://googlechromereleases.blogspot.com/2013/03/stable-channel-update-for-chrome-os_15.html
... Release highlights:
- Updated Flash to 11.6.602.180, which resolves a bug where some DRM video content would be unable to play (e.g.: Amazon Prime Video).
- Fixed an issue with Chromebook Pixel and Acer C7 systems freezing while playing videos.
- Fixed an issue with Acer C7 systems freezing after resume...
:fear:
AplusWebMaster
2013-03-27, 12:43
FYI...
Chrome v26.0.1410.43 released
- https://secunia.com/advisories/52761/
Release Date: 2013-03-27
Criticality level: Highly critical
Impact: Unknown, Security Bypass, System access
Where: From remote
CVE Reference(s): CVE-2013-0916, CVE-2013-0917, CVE-2013-0918, CVE-2013-0919, CVE-2013-0920, CVE-2013-0921, CVE-2013-0922, CVE-2013-0923, CVE-2013-0924, CVE-2013-0925, CVE-2013-0926
... vulnerabilities are reported in versions prior to 26.0.1410.43.
Solution: Upgrade to version 26.0.1410.43.
Original Advisory:
- http://googlechromereleases.blogspot.dk/2013/03/stable-channel-update_26.html
- http://h-online.com/-1831304
27 March 2013
:fear::fear:
AplusWebMaster
2013-04-10, 12:00
FYI...
Chrome v26.0.1410.64 released
- https://secunia.com/advisories/52983/
Release Date: 2013-04-10
Criticality level: Highly critical
Impact: System access
Where: From remote ...
For more information: https://secunia.com/SA52931/
Solution: Update to version 26.0.1410.63 for Mac and Linux or 26.0.1410.64 for Windows.
Original Advisory:
http://googlechromereleases.blogspot.dk/2013/04/stable-channel-update.html
"... This release contains stability improvements, and a new version of Adobe Flash..."
___
Flash Player Update
- http://googlechromereleases.blogspot.dk/2013/05/flash-player-update.html
May 14, 2013 - "We are currently updating Flash Player to 11.7.700.202 for Windows and Mac to all Stable channel (Chrome 26) users."
:fear:
AplusWebMaster
2013-05-21, 20:25
FYI...
Chrome v27.0.1453.93 released
- http://googlechromereleases.blogspot.ca/2013/05/stable-channel-release.html
May 21, 2013 - "Chrome 27.0.1453.93 for Windows, Mac, Linux, and Chrome Frame contains a number of new items... ongoing internal security work was as usual responsible for a wide range of fixes..."
- https://secunia.com/advisories/53430/
Release Date: 2013-05-22
Criticality level: Highly critical
Impact: Unknown, Cross Site Scripting, Exposure of sensitive information, System access
Where: From remote ...
CVE Reference(s): CVE-2013-2728, CVE-2013-2836, CVE-2013-2837, CVE-2013-2839, CVE-2013-2840, CVE-2013-2841, CVE-2013-2842, CVE-2013-2843, CVE-2013-2844, CVE-2013-2845, CVE-2013-2846, CVE-2013-2847, CVE-2013-2848, CVE-2013-2849, CVE-2013-3324, CVE-2013-3325, CVE-2013-3326, CVE-2013-3327, CVE-2013-3328, CVE-2013-3329, CVE-2013-3330, CVE-2013-3331, CVE-2013-3332, CVE-2013-3333, CVE-2013-3334, CVE-2013-3335
... For more information: https://secunia.com/SA53419/
Solution: Update to version 27.0.1453.93.
- http://h-online.com/-1867731
22 May 2013
:fear::fear:
AplusWebMaster
2013-06-05, 12:18
FYI...
Chrome v27.0.1453.110 released
- https://secunia.com/advisories/53681/
Release Date: 2013-06-05
Criticality level: Highly critical
Impact: Unknown, System access
Where: From remote
CVE Reference(s): CVE-2013-2854, CVE-2013-2855, CVE-2013-2856, CVE-2013-2857, CVE-2013-2858, CVE-2013-2859, CVE-2013-2860, CVE-2013-2861, CVE-2013-2862, CVE-2013-2863, CVE-2013-2864, CVE-2013-2865
... vulnerabilities are reported in versions prior to 27.0.1453.110.
Solution: Update to version 27.0.1453.110.
Original Advisory:
- http://googlechromereleases.blogspot.com/search/label/Stable%20updates
June 4, 2013 - "... updated to 27.0.1453.110 for Windows, Macintosh, Linux and Chrome Frame platforms..."
- http://h-online.com/-1882885
5 June 2013
:fear::fear:
AplusWebMaster
2013-06-12, 15:37
FYI...
Chrome/Flash update to 11.7.700.225
- http://googlechromereleases.blogspot.com/2013/06/flash-player-update-for-stable-channel.html
June 11, 2013 - "Flash Player Update for Stable Channel / We are currently updating Flash Player to 11.7.700.225* for Windows and Mac to all Stable channel (Chrome 27) users."
* https://www.adobe.com/support/security/bulletins/apsb13-16.html
:fear:
AplusWebMaster
2013-06-19, 14:44
FYI...
Chrome v27.0.1453.116 released
- https://secunia.com/advisories/53867/
Release Date: 2013-06-19
Impact: Cross Site Scripting
Where: From remote ...
CVE Reference: CVE-2013-2866
... vulnerability is caused due to an error when handling opacity of embedded Flash elements and can be exploited to e.g. gain access to the system's camera and microphone by tricking the user into clicking Flash settings frame disguised as a normal graphical element. The vulnerability is reported in versions prior to 27.0.1453.116.
Solution: Update to version 27.0.1453.116.
Original Advisory: http://googlechromereleases.blogspot.com/2013/06/stable-channel-update_18.html
:fear: