Comment 1 for bug 1099075

Revision history for this message
ilf (ilf) wrote :

And again: 24.0.1312.56

Security fixes:

* [$1000] [151008] High CVE-2013-0839: Use-after-free in canvas font handling. Credit to Atte Kettunen of OUSPG.
* [170532] Medium CVE-2013-0840: Missing URL validation when opening new windows.
* [169770] High CVE-2013-0841: Unchecked array index in content blocking. Credit to Google Chrome Security Team (Chris Evans).
* [166867] Medium CVE-2013-0842: Problems with NULL characters embedded in paths. Credit to Google Chrome Security Team (Jüri Aedla).
* [Mac only] [166523] High CVE-2013-0843: Crash with unsupported RTC sampling rate. Credit to Ted Nakamura of the Chromium development community.

I don't know why you edited this out of my original description:

"From a security perspective, having no Chromium package at all would be better than having outdated ones with gaping holes."