In yet another update, Chrome stable and beta channels have been updated to 10.0.648.204. The latest update mitigates six vulnerabilities identified by various security researchers, and resolves performance and stability issues. The update also includes support for password manager on Linux. . The release patches a buffer error in base string handling first identified by Alex Turpin. Security professionals at Google have resolved stale pointer in handling of Cascading Style Sheets (CSS) and SVG text handling, both identified by Sergey Glazunov. The update fixes a DOM tree corruption issue with broken node parentage. Use-after-free issues in the frame loader and HTML collection have been mitigated in the new Chrome channel. While the issue with frame loader was detected by Sławomir Błażek, Sergey Glazunov identified the issue with HTML collection. Use-after-free issue takes place, when memory is deallocated, but regained later. All the six vulnerabilities have been rated as high-risk. Google rates bugs as critical, high, medium and low. According to the company. The latest Firefox update fixes several crashes and enhances overall stability while patching four critical security flaws.. Chrome Update, Security Enhancement, High-Risk Fix. . LinuxSecurity.com Team
Google has released version 10.0.648.204 of its Chrome web browser, a maintenance and security update to the Chrome 10 stable branch. The update addresses a total of six vulnerabilities in the WebKit-based browser that can be "exploited by malicious people to compromise a system" and rates all of them with a "High" priority. Secunia, for example, rates the vulnerabilities as highly critical.. According to Google, one of the high risk issues relates to a buffer error in base string handling, while two others have to do with use-after-free, where memory is deallocated but later accessed, in the frame loader and in HTMLCollection. The other issues range from a stale pointer in CSS handling and in SVG text handling, as well as a DOM tree corruption bug. The update also includes several performance and stability fixes and adds support for the browser's password manager on Linux systems. As part of its Chromium Security Reward programme, Google rewarded those who reported security vulnerabilities with a total of $8,500, of which $7,000 went to developer Sergey Glazunov alone. Further details of the Chrome vulnerabilities are being withheld until "a majority of users are up-to-date with the fix". The link for this article located at H Security is no longer available. . The recent update from Microsoft addresses multiple critical vulnerabilities, such as heap corruption and privilege escalation flaws within Windows.. Chrome 10 Update, Google Browser Security, Memory Management Issue. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.