Google is updating the stable version of its Chrome Web browser for Windows, Mac and Linux, addressing a handful of security vulnerabilities -- including four that could put users at risk simply by viewing a maliciously constructed image file.. Those vulnerabilities addressed in Chrome 5.0.375.99 are rated as "high" severity, and include a high-memory corruption flaw that could be triggered by an invalid PNG image file. Google awarded security researcher Aki Helin $1,000 for the discovery of the vulnerability, which he reported June 7. However, because the flaw is actually rooted in the open source libpng program -- which is also in use by other Web browsers and open source applications -- Helin later suggested in Google's tracking system that the company help mitigate the risk to other browsers and applications still using a vulnerable version of libpng by holding off on fixing the vulnerability, which would have thereby publicly revealed it. Instead, Helin suggested that the best approach might be to sync the Google Chrome patch with an update from the upstream libpng project, which ultimately issued its security bug update for the issue on June 25. The link for this article located at eSecurity Planet is no longer available. . The new Firefox version tackles significant vulnerabilities, highlighting a severe security concern related to file processing for its users.. Chrome Update, High Severity Security Flaw, Libpng Issue, Browser Security, Open Source Vulnerability. . LinuxSecurity.com Team
A flaw in the way the Firefox and Opera browsers handle an image file could allow an attacker to see what Web sites a person has visited. The problem concerns how the two browsers handle a ".BMP," or bitmap, image file, according to an advisory written by Gynvael Coldwind of Vexillium.org, who posted a video illustrating the problem. I always find it interesting when two pieces of software together can cause a security vulnerability.. The link for this article located at Network World is no longer available. . Recent investigations reveal a critical vulnerability in Opera and Firefox that risks user web history due to improper handling of image files and metadata extraction. Web History Exploit, Browser Image Flaw, User Privacy Breach. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.