Lucene search

K
chromeHttps://chromereleases.googleblog.comGCSA-8759772237478383156
HistoryFeb 24, 2014 - 12:00 a.m.

Stable Channel Update for Chrome OS

2014-02-2400:00:00
https://chromereleases.googleblog.com
chromereleases.googleblog.com
14

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

EPSS

0.001

Percentile

47.7%

Update: Samsung Chromebook has been updated to 33.0.1750.124 (Platform version: 5116.88.2)

The Stable channel has been updated to 33.0.1750.124 (Platform version: 5116.88.0) for all Chrome OS devices except Samsung Chromebook. This build contains a number of bug fixes, security updates and feature enhancements. Systems will be receiving updates over the next several days.

Some highlights of these changes are:

  • Added policies for admins to set/allow avatar for public sessions.
  • Enabled the ability to playback content protected videos in HD in all ARM devices.
  • Enabled people search for contacts in the launcher. You can start a Hangouts chat or email them.
  • New first-run UI to provide a more lightweight, polished, and personalized experience.

Security fixes and rewards:

We highlight fixes contributed by external researchers or particularly interesting. Please see the Chromium security page for more information.

  • [$1000][306959] Medium CVE-2013-6659: Issue with certificates validation in TLS handshake. Credit to Antoine Delignat-Lavaud and Karthikeyan Bhargavan from Prosecco, Inria Paris.
  • [328620] GPU sandbox would be disabled in certain situations. Credit to Julien Tinnes of Google Chrome Security Team.
  • [336284] User login whitelist could be bypassed in certain situations.
    If you find new issues, please let us know by visiting our forum or filing a bug. Interested in switching channels? Find out how. You can submit feedback using 'Report an issue…' in the Chrome menu (3 horizontal bars in the upper right corner of the browser).

Dharani Govindan
Google Chrome

Affected configurations

Vulners
Node
googlechrome_osRange<33.0.1750.124

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

EPSS

0.001

Percentile

47.7%