Critical Google Chrome hole plugged in 24 hours
arstechnica.com
Critical Google Chrome hole plugged in 24 hours
1–10 of 26 posts
Re: Critical Google Chrome hole plugged in 24 hours
#2I notice that pretty much every time I read articles about Pwn2Own and similar. It's high time that Flash was abandoned as a ubiquitous part of the web. It is to web development as Outlook Express was to desktop software in the 90s - sure it's everywhere, but it's not doing much good by being so.
Re: Critical Google Chrome hole plugged in 24 hours
#3Re: Critical Google Chrome hole plugged in 24 hours
#4With a response time like that it seems like antivirus software is becoming increasingly irrelevant.
Re: Critical Google Chrome hole plugged in 24 hours
#5With a response time like that it seems like antivirus software is becoming increasingly irrelevant.
Meanwhile, critical Android security holes remain unpatched for more than 2 yrs.
Re: Critical Google Chrome hole plugged in 24 hours
#6And that the SVN commit history is available: http://build.chromium.org/f/chromium/perf/dashboard/ui/chang...
But I don't see any commit that look even remotely related to this exploit. What's up?
Re: Critical Google Chrome hole plugged in 24 hours
#7The Chrome Release blog says it's fixed: http://googlechromereleases.blogspot.com/2012/03/chrome-stab... And that the SVN commit history is available: http://build.chromium.org/f/chromium/perf/dashboard/ui/chang... But I don't see any commit that look even remotely related to this exploit. What's up?
By committing the fix, they would effectively be releasing a step-by-step guide on how to exploit the vulnerability.
Re: Critical Google Chrome hole plugged in 24 hours
#8The Chrome Release blog says it's fixed: http://googlechromereleases.blogspot.com/2012/03/chrome-stab... And that the SVN commit history is available: http://build.chromium.org/f/chromium/perf/dashboard/ui/chang... But I don't see any commit that look even remotely related to this exploit. What's up?
Well... They would hopefully be smarter than committing the fix to the public SVN. By committing the fix, they would effectively be releasing a step-by-step guide on how to exploit the vulnerability.
Certainly if you build Chromium from git/SVN now, the bug is fixed.
I just find it a little strange that their changelog / list of commits in each version is not true.
Re: Critical Google Chrome hole plugged in 24 hours
#9"To date, most successful attacks against Chrome exploit Adobe Flash, which is protected by a significantly more porous sandbox." I notice that pretty much every time I read articles about Pwn2Own and similar. It's high time that Flash was abandoned as a ubiquitous part of the web. It is to web development as Outlook Express was to desktop software in the 90s - sure it's everywhere, but it's not doing much good by be…
Re: Critical Google Chrome hole plugged in 24 hours
#10Earlier quoted context omitted.
Meanwhile, critical Android security holes remain unpatched for more than 2 yrs.
A real security hole, or one like "if someone watches you type your PIN code, they'll know your PIN code"?