Google Chrome 0.2.149.29 Released

Given the recent waves of full disclosure for exploits involving Chrome the developers took the call to action seriously, addressed the bugs and have now made available for download Google Chrome 0.2.149.29.

In order to upgrade to the latest version users are required to perform a manual check or optionally, let Chrome do it itself. Chrome automatically checks for updates every five hours and when an update is avaialble it will be downloaded and applied during the next browser restart.

Changelog for the new version:

Security Updates:

Fix a buffer overflow vulnerability in handling long filenames that display in the Save As... dialog. This is a critical risk that could lead to execution of arbitrary code.

Issue: http://code.google.com/p/chromium/issues/detail?id=1414

Fix: http://src.chromium.org/viewvc/chrome?view=rev&revision=1766

Fix a buffer overflow vulnerability in handling link targets displayed in the status area when the user hovers over a link. This is a critical risk that could lead to execution of arbitrary code.

Issue: reported internally to Google

Fix: http://src.chromium.org/viewvc/chrome?view=rev&revision=1797

Fix an out-of-bounds memory read when parsing URLs ending with :%. This is a low risk that can be used to crash the entire browser, possibly causing loss of data in the current session.

Issue: http://code.google.com/p/chromium/issues/detail?id=122

Fix: http://src.chromium.org/viewvc/chrome?view=rev&revision=1760

Change the default Downloads directory if it is set to Desktop, and ensure that Desktop cannot be the default. This mitigates the risk of malicious cluttering of the desktop with unwanted downloads, which can lead to executing unwanted files.

Fix: http://src.chromium.org/viewvc/chrome?view=rev&revision=1793

 

Other changes:

Fix a couple of data transfer issues with the Safe Browsing service causing unnecessary traffic.

Fix: http://src.chromium.org/viewvc/chrome?view=rev&revision=1762

Fix a JavaScript bug that affected facebook.com. The fix properly handles negative indicies when using for...in.

Issue: http://code.google.com/p/chromium/issues/detail?id=131

Fix: http://src.chromium.org/viewvc/chrome?view=rev&revision=1763

Fix search suggestions not working properly for http://search.daum.net/, http://search.empas.com/, http://meta.ua/, http://search.naver.com/, and http://search.yahoo.com/ on several non-United States sites.

Fix:http://src.chromium.org/viewvc/chrome?view=rev&revision=1759

Permalink: Google Chrome 0.2.149.29 Released (bookmark@delicious)