Anzeigen der neuesten Beiträge
0 Mitglieder und 4 Gäste betrachten dieses Thema.
The Chrome Team is excited to announce the promotion of Chrome 22 to the stable channel. Chrome 22.0.1229.79 (also now available on the beta channel) has a number of new and exciting updates including: Mouse Lock API availability for Javascript Additional Windows 8 enhancements Continued polish for users of HiDPI/Retina screensYou can find out more about Chrome 22 on the Official Chrome Blog.Security fixes and rewards:Please see the Chromium security page for more detail. Note that the referenced bugs may be kept private until a majority of our users are up to date with the fix.Occasionally, we issue special rewards for bugs outside of Chrome, particularly where the bug is very severe and/or we are able to partially work around the issue: [$5000] [146254] Critical CVE-2012-2897: Windows kernel memory corruption. Credit to Eetu Luodemaa and Joni Vähämäki, both from Documill.And back to your regular scheduled rewards, including some at the new higher levels: [$10000] [143439] High CVE-2012-2889: UXSS in frame handling. Credit to Sergey Glazunov. [$5000] [143437] High CVE-2012-2886: UXSS in v8 bindings. Credit to Sergey Glazunov. [$2000] [139814] High CVE-2012-2881: DOM tree corruption with plug-ins. Credit to Chamal de Silva. [$1000] [135432] High CVE-2012-2876: Buffer overflow in SSE2 optimizations. Credit to Atte Kettunen of OUSPG. [$1000] [140803] High CVE-2012-2883: Out-of-bounds write in Skia. Credit to Atte Kettunen of OUSPG. [$1000] [143609] High CVE-2012-2887: Use-after-free in onclick handling. Credit to Atte Kettunen of OUSPG. [$1000] [143656] High CVE-2012-2888: Use-after-free in SVG text references. Credit to miaubiz. [$1000] [144899] High CVE-2012-2894: Crash in graphics context handling. Credit to Sławomir Błażek. [Mac only] [$1000] [145544] High CVE-2012-2896: Integer overflow in WebGL. Credit to miaubiz. [$500] [137707] Medium CVE-2012-2877: Browser crash with extensions and modal dialogs. Credit to Nir Moshe. [$500] [139168] Low CVE-2012-2879: DOM topology corruption. Credit to pawlkt. [$500] [141651] Medium CVE-2012-2884: Out-of-bounds read in Skia. Credit to Atte Kettunen of OUSPG. [132398] High CVE-2012-2874: Out-of-bounds write in Skia. Credit to Google Chrome Security Team (Inferno). [134955] [135488] [137106] [137288] [137302] [137547] [137556] [137606] [137635] [137880] [137928] [144579] [145079] [145121] [145163] [146462] Medium CVE-2012-2875: Various lower severity issues in the PDF viewer. Credit to Mateusz Jurczyk of Google Security Team, with contributions by Gynvael Coldwind of Google Security Team. [137852] High CVE-2012-2878: Use-after-free in plug-in handling. Credit to Fermin Serna of Google Security Team. [139462] Medium CVE-2012-2880: Race condition in plug-in paint buffer. Credit to Google Chrome Security Team (Cris Neckar). [140647] High CVE-2012-2882: Wild pointer in OGG container handling. Credit to Google Chrome Security Team (Inferno). [142310] Medium CVE-2012-2885: Possible double free on exit. Credit to the Chromium development community. [143798] [144072] [147402] High CVE-2012-2890: Use-after-free in PDF viewer. Credit to Mateusz Jurczyk of Google Security Team, with contributions by Gynvael Coldwind of Google Security Team. [144051] Low CVE-2012-2891: Address leak over IPC. Credit to Lei Zhang of the Chromium development community. [144704] Low CVE-2012-2892: Pop-up block bypass. Credit to Google Chrome Security Team (Cris Neckar). [144799] High CVE-2012-2893: Double free in XSL transforms. Credit to Google Chrome Security Team (Cris Neckar). [145029] [145157] [146460] High CVE-2012-2895: Out-of-bounds writes in PDF viewer. Credit to Mateusz Jurczyk of Google Security Team, with contributions by Gynvael Coldwind of Google Security Team. [Linux only] [137541] Critical CVE-2012-2859: Crash in tab handling. Credit to Jeff Roberts of Google Security Team. [137671] Medium CVE-2012-2860: Out-of-bounds access when clicking in date picker. Credit to Chamal de Silva.Many of the above bugs were detected using AddressSanitizer.We’d also like to thank Arthur Gerkis for working with us during the development cycle and preventing security regressions from ever reaching the stable channel.Full details about what's in this release are available in the SVN revision log.
Desktop New partner content DSK-374043 IRC icon went missing DSK-374003 Leaks memory for every displayed mail message DSK-374302 Support Outlook.com in Opera Mail DSK-373894 Mail incorrectly assumes IMAP port on setup DSK-373098 The low-bandwidth mode toolbar is not shown immediately DSK-374353 Don't show unread messages count in trash DSK-371541 Don't show spam in unread by default DSK-371402 Compose mail action doesn't work from Notes DSK-372454 No layout icons in mail layout dialog DSK-373897 Deleting user stylesheet file location at Preferences crashes DSK-371699 Link gestures don't work when holding ctrl DSK-373987 Improve the message for blocking installation of off-store extensions and provide domain in the dialog DSK-358761 Badge dialog shouldn't be affected by maximize/minimize mouse gestures DSK-310156 Restored closed window shows only the Speed Dial when the window was closed by closing last tab DSK-338722 Historical URLs in Speed Dial add dialog stay on top of all apps DSK-374644 Bookmark star icon always yellow even for non-favorited sites DSK-363692 'show address in caption' option is gone DSK-372995 Speed dial favicon in private tab is incorrect DSK-356893 Bookmarks favicons fetching triggers recreation of deleted bookmarks after using LinkWindows DSK-373951 Window borders not painted when started with theme applied DSK-373996 Files with Norwegian symbols in their name fail to open using an external applicationLinux/FreeBSD DSK-373361 Implement horizontal mouse wheel handlingOS X Move plug-ins back into the main process Various small icons at Retina sizes DSK-372208 Text selection can lock UI when dragging DSK-373976 Webfont FranklinGothicFSBook fails to render DSK-373622 Update gstreamer libraries DSK-374245 Memory leak on start-up on OS X 10.8 DSK-373118 Crash when dragging label in Label dialog DSK-371133 Plugin wrappers not killed after closing window with plug-ins DSK-363839 Repainting of form elements after animationCore CORE-46906 Reading out selections in textarea fails - Wikipedia "search and replace" functionality is malfunctioning CT-3560 Cannot load engadget.com CORE-48074 Crash when handling keypress event CORE-47582 Performance regression (sic)
Here's a summary of the changes: Gtk UI Podcast dialog: Section changing and Flattr bug (bug 1636) Improvements to the Flattr Integration Extensions Minimize on start (bug 1633) TED Talks Subtitles (pull request #9) Gtk status icon (bug 1495) Correct typo in the rename_download extension Device Synchronization Fix syncing with utf8-incompatible file names Sortable dates for file names on sync device Translations New translation: Persian (Iran) Updated translations: Basque, Galician, Hebrew, Dutch, Portuguese, Italian and German YouTube Integration Fix YouTube download URL resolving (bug 1665) Parse error messages, improve downloading Feedcore (Feed Parsing) Fix feed autodiscovery (bug 1672) Check feedparser version (bug 1648) QML UI (MeeGo 1.2 Harmattan / N950 / N9) Filters for unfinished downloads (bug 1655) Show pubdate and file size (bug 1640) Remove remaining Maemo 5 (Fremantle) support Remember episode list scroll position (bug 1660) Honor pause_subscription flag (bug 1641) Download resuming (bug 1487) New and Removed Core Features Remove moving files to the "Unknown" folder (bug 1612) Respect GPODDER_DOWNLOAD_DIR in the environment (bug 466) Bugfixes Decode enclosure filename properly (bug 1663) Use sanitize_filename function (bug 1638) Model: Fix update issues with custom feeds Util: make object_string_formatter more robust Various minor bugfixes, clean-ups and corrections