In association with heise online

23 June 2009, 09:50

Google closes critical vulnerability in Chrome 2

  • Twitter
  • Facebook
  • submit to slashdot
  • StumbleUpon
  • submit to reddit

Less than two weeks after the last vulnerabilities were closed, Google has released version 2.0.172.33 of Chrome 2, a security update fixing another critical vulnerability in its web browser based on Apple’s open source WebKit browser application framework. The cause of the vulnerability is a buffer overflow when processing certain responses from HTTP servers. A specially crafted response from a server could be used to crash the browser, or allow an attacker to remotely execute arbitrary code. Further details of the vulnerability, however, are currently being withheld until "a majority of users are up to date with the fix". In addition, the developers also addressed two network issues, however, they are not security related.

Users that currently have Chrome installed can use the built-in update function by clicking Tools, selecting About Google Chrome and clicking the Update button. According to a recent joint study by Google Switzerland and the ETH (Swiss Federal Institute of Technology) in Zurich, automatically updating without requiring user confirmation is the most successful way to ensure a high rate of distribution of the latest release and consequently a low number of vulnerable browsers.

See also:

(crve)

Print Version | Send by email | Permalink: http://h-online.com/-742151
 


  • July's Community Calendar





The H Open

The H Security

The H Developer

The H Internet Toolkit