Google heeft een update voor versie 35 van zijn webbrowser Chrome uitgebracht. Google Chrome is beschikbaar in drie verschillende uitvoeringen: stable, beta en dev, en ditmaal is de stabiele uitvoering bijgewerkt. In versie 35 hebben onder meer webdesigners meer controle over touch-input, zijn er nieuwe javascript-mogelijkheden en zijn er diverse apps en extensies toegevoegd. Deze update bevat drie beveiligingsupdates en er is een nieuwe versie van de Adobe Flash Player aanwezig.
Stable Channel Update
The Stable Channel has been updated to 35.0.1916.153 for Windows, Mac and Linux. This release contains a Flash Player update.
Security Fixes and Rewards
This update includes 4 security fixes. Below, we highlight fixes that were either contributed by external researchers or particularly interesting. Please see the Chromium security page for more information.As usual, our ongoing internal security work was responsible for the following fix:
- [369525] High CVE-2014-3154: Use-after-free in filesystem api. Credit to Collin Payne.
- [369539] High CVE-2014-3155: Out-of-bounds read in SPDY. Credit to James March, Daniel Sommermann and Alan Frindell of Facebook.
- [369621] Medium CVE-2014-3156: Buffer overflow in clipboard. Credit to Atte Kettunen of OUSPG.
Many of the above bugs were detected using AddressSanitizer. This release fixes a number of crashes and other bugs. A full list of changes is available in the SVN log. If you find a new issue, please let us know by filing a bug.
- [368980] CVE-2014-3157: Heap overflow in media.