Tag Archive: 3.0

Since the release of Apple’s latest operating system, Snow Leopard (10.6), there have been two main patches. These have both been relatively minor in terms of fixes and changes, though the latest update, 10.6.3, aims to be a bit more substantial when it comes to upgrades.

As discovered by Hardmac forums, the beta of the 10.6.3 update includes OpenGL 3.0 support, bringing many more graphical capabilities to the operating system. As AppleInsider noted, graphics cards found in Mac computers support OpenGL 3.0, so the only step now is to improve the software somewhat; a step being taken in the latest update. So far, 22 out of 23 extensions are now supported, though the majority of the associated OpenGL 3.0-specific functions are yet to have support in 10.6.3.

Backwards compatibility is said to be there in 10.6.3, as one would expect; in addition to that, support for OpenGL 3.1 is at 12 percent, whereas OpenGL 3.2 is a bit further, sitting currently on 33 percent. If you’re a Mac user, the latest update will hopefully become available soon, as Apple seems to be progressing quickly with it.

Google Chrome’s Stable channel has been updated to version 3.0.195.38. (The Stable channel is still Windows-only.)

This release fixes a couple of browser crashes:

  • r31694 fixes a crash while typing in the omnibox (issue 20511).
  • r32474 fixes a crash while playing mp4 videos with odd sizes, such as 1366×768 (issue 27675).

–Mark Larson,
Google Chrome Team

Download: Google Chrome 3.0.195.38

Google Chrome’s Stable channel has been updated to 3.0.195.33 to fix a potential issue that could cause Google Chrome to stop working and a security issue.

This release removes a dependency on a Windows library (t2embed.dll) that is not required by Google Chrome. If that library is missing or the user does not have permission to read it, earlier versions of Google Chrome would fail silently.

Security Fix:
CVE-2009-2816 Custom headers incorrectly sent for CORS OPTIONS request

A malicious web site operator could set custom HTTP headers on cross-origin OPTIONS requests.

More info: https://bugs.webkit.org/show_bug.cgi?id=28446, http://support.apple.com/kb/HT3949

Severity: Low. The majority of users are unlikely to be impacted by this issue.
Credit: Apple Security

Mitigations:

  • A victim would need to visit a page under an attacker’s control.
  • The OPTIONS attribute is not widely supported by servers.

Mark Larson
Google Chrome Team

Download: Google Chrome 3.0.195.33

The stable channel has been updated to 3.0.195.32, and includes the following security and stability fixes:
  • Resolved a history issue that affected going back from queries in Google Maps. (Issue: 21353)
  • Fixed issue with Adobe Acrobat Reader 9.2, where no content would be displayed. (Issue: 24883)
  • Fixed an infinite loop in AAC decoding. (Webkit Issue: 27239)
  • Fixed a top crasher. (Issue: 22205)
  • Fix issues where setInterval sometimes eats 100% CPU. (Issue: 25892)

Security Fixes:

CVE-2009-XXXX User not warned for some file types that can execute JavaScript

The user was not warned about certain possibly dangerous file types such as SVG, MHT and XML files. In some browsers, JavaScript can execute within these types of files. Because the JavaScript runs in the local context, it may be able to access local resources.

More info: http://code.google.com/p/chromium/issues/detail?id=23979
(This issue will be made public once a majority of users are up to date with the fix.)

Severity: Medium
Credit:Inferno of SecureThoughts.com
Mitigations:

  • A victim would need to visit a page under an attacker’s control.
  • The victim would furthermore need to open a malicious file.

CVE-2009-XXXX Possible memory corruption in the Gears plugin

A malicious site could use the Gears SQL API to put SQL metadata into a bad state, which could cause a subsequent memory corruption. This may lead to a Gears plugin crash or possibly arbitrary code execution.

More info: http://code.google.com/p/chromium/issues/detail?id=26179
(This issue will be made public once a majority of users are up to date with the fix.)


Severity: High
Credit:This issue was found by the Google Chrome security team.
Mitigations:

  • A victim would need to visit a page under an attacker’s control.
  • The victim would furthermore need to “click-through” the Gears dialog confirming that they trust the attacker’s evil page.

Anthony Laforge
Google Chrome Program Manager

Download: Google Chrome 3.0.195.32

Enter your email address:

Delivered by FeedBurner