- Dołączył
- 4 Czerwiec 2013
- Posty
- 7200
- Reakcje/Polubienia
- 47
Security fixes:
[334897] High CVE-2013-6652: Issue with relative paths in Windows sandbox named pipe policy. Credit to tyranid.
[331790] High CVE-2013-6653: Use-after-free related to web contents. Credit to Khalil Zhani.
[333176] High CVE-2013-6654: Bad cast in SVG. Credit to TheShow3511.
[293534] High CVE-2013-6655: Use-after-free in layout. Credit to cloudfuzzer.
[331725] High CVE-2013-6656: Information leak in XSS auditor. Credit to NeexEmil.
[$1000][331060] Medium CVE-2013-6657: Information leak in XSS auditor. Credit to NeexEmil.
[322891] Medium CVE-2013-6658: Use-after-free in layout. Credit to cloudfuzzer.
[306959] Medium CVE-2013-6659: Issue with certificates validation in TLS handshake. Credit to Antoine Delignat-Lavaud and Karthikeyan Bhargavan from Prosecco, Inria Paris.
[332579] Low CVE-2013-6660: Information leak in drag and drop. Credit to bishopjeffreys.
[344876] Low-High CVE-2013-6661: Various fixes from internal audits, fuzzing and other initiatives. Of these, seven are fixes for issues that could have allowed for sandbox escapes from compromised renderers.
[344492] High CVE-2013-6663: Use-after-free in svg images.
[326854] High CVE-2013-6664: Use-after-free in speech recognition. .
[337882] High CVE-2013-6665: Heap buffer overflow in software rendering.
[332023] Medium CVE-2013-6666: Chrome allows requests in flash header request.
As usual, our ongoing internal security work responsible for a wide range of fixes:
[348175] CVE-2013-6667: Various fixes from internal audits, fuzzing and other initiatives.
[343964, 344186, 347909] CVE-2013-6668: Multiple vulnerabilities in V8 fixed in version 3.24.35.10.
Main improvements:
Ogg Opus support
Bug-/Securityfixes
improved performance
Youtube problems fixed