|
|
Google Chrome 0.4.154.29 BetaGoogle - 476KB (Open Source) -![]() |
This release upgrades Gears to 0.5.4.2 to address a security issue with Gears 0.5.4.0 and earlier versions:
Gears Cross-Origin Worker Vulnerability
CVE: CVE-2008-5258
A vulnerability in Gears could allow an attacker to run code in the context of a site that serves user-controlled files. To exploit this, an attacker needs to upload a malicious file to the victim's site and convince the user to allow the attacker's site to use Gears.
Severity: High. Even though this requires convincing users to allow a third-party site to use Gears, it could allow data theft and cross-site scripting on sites hosting user-created content, even those that do not use Gears.
Credit: Thanks to Yair Amit, Senior Security Researcher, IBM Rational Application Security Research Team for responsibly reporting the issue to Google.
This release also contains a fix to stop crashes while dragging tabs on computers running Windows Vista.
Gears Cross-Origin Worker Vulnerability
CVE: CVE-2008-5258
A vulnerability in Gears could allow an attacker to run code in the context of a site that serves user-controlled files. To exploit this, an attacker needs to upload a malicious file to the victim's site and convince the user to allow the attacker's site to use Gears.
Severity: High. Even though this requires convincing users to allow a third-party site to use Gears, it could allow data theft and cross-site scripting on sites hosting user-created content, even those that do not use Gears.
Credit: Thanks to Yair Amit, Senior Security Researcher, IBM Rational Application Security Research Team for responsibly reporting the issue to Google.
This release also contains a fix to stop crashes while dragging tabs on computers running Windows Vista.
Latest updates
- 14 Feb 12 -
Maxthon 3.3.4.3000 - 14 Feb 12 -
Shockwave Player 11.6.4.634 - 14 Feb 12 -
Gladinet Cloud Desktop 4.0.839 - 14 Feb 12 -
TortoiseSVN 1.7.5 - 14 Feb 12 -
DAEMON Tools Lite 4.45.3
Copy the following code to link to this page:
DownloadThis Version
476KB
EN



