<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Google Chrome Hacks Blog- Useful Tips, Hacks, and News about the Google Chrome Browser! &#187; Chrome Security Flaws/Bugs</title>
	<atom:link href="http://chrome-hacks.net/category/chrome-security-flawsbugs/feed/" rel="self" type="application/rss+xml" />
	<link>http://chrome-hacks.net</link>
	<description>Useful Tips, Hacks, and News about the Google Chrome Browser!</description>
	<lastBuildDate>Fri, 14 May 2010 16:54:27 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Chrome Security Alert &#8211; Carriage Return Null Object Memory Exhaustion Remote Dos</title>
		<link>http://chrome-hacks.net/2008/06/25/chrome-security-alert-carriage-return-null-object-memory-exhaustion-remote-dos/</link>
		<comments>http://chrome-hacks.net/2008/06/25/chrome-security-alert-carriage-return-null-object-memory-exhaustion-remote-dos/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 00:05:35 +0000</pubDate>
		<dc:creator>Max</dc:creator>
				<category><![CDATA[Chrome Security Flaws/Bugs]]></category>
		<category><![CDATA[carriage return]]></category>
		<category><![CDATA[denial of service]]></category>
		<category><![CDATA[dos version]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[javascript function]]></category>
		<category><![CDATA[memory exhaustion]]></category>
		<category><![CDATA[memory leak problem]]></category>
		<category><![CDATA[memory usage]]></category>
		<category><![CDATA[null object]]></category>
		<category><![CDATA[object memory]]></category>
		<category><![CDATA[pop ups]]></category>
		<category><![CDATA[proof of concept]]></category>
		<category><![CDATA[resultant system]]></category>
		<category><![CDATA[security alert]]></category>
		<category><![CDATA[sood]]></category>
		<category><![CDATA[task manager]]></category>
		<category><![CDATA[time user]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://chrome-hacks.net/?p=225</guid>
		<description><![CDATA[Here&#8217;s a security alert for Google Chrome, it seems like some kind of memory leak problem with the Enter key:
*Google Chrome Carriage Return Null Object Memory Exhaustion Remote Dos.*
*Version Affected:*
Chrome/0.2.149.30
Chrome/0.2.149.29
*Severity:*
High
*Description:*
The Google chrome browser is vulnerable to memory exhaustion based
denial of
service which can be triggered remotely.The vulnerability triggers when
Carriage
Return(\r\n\r\n) is passed as an argument to window.open() [...]]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s a security alert for Google Chrome, it seems like some kind of memory leak problem with the Enter key:</p>
<blockquote><p>*Google Chrome Carriage Return Null Object Memory Exhaustion Remote Dos.*</p>
<p>*Version Affected:*<br />
Chrome/0.2.149.30<br />
Chrome/0.2.149.29</p>
<p>*Severity:*<br />
High</p>
<p>*Description:*<br />
The Google chrome browser is vulnerable to memory exhaustion based<br />
denial of<br />
service which can be triggered remotely.The vulnerability triggers when<br />
Carriage<br />
Return(\r\n\r\n) is passed as an argument to window.open() function. It<br />
makes the<br />
Google Chrome to generate number of windows at the same time thereby<br />
leading<br />
to memory exhaustion. The behavior can be easily checked by looking at<br />
the task<br />
manager as with no time the memory usage rises high. The problem lies in<br />
the handling<br />
of object and its value returned by the javascript function. Once it is<br />
triggered the pop<br />
ups are started generating. The Google Chrome browser generate object<br />
windows continuously<br />
there by affecting memory of the resultant system. Probably it can be<br />
crashed within no time.<br />
User interaction is required in this.</p>
<p>*Proof of Concept*<br />
http://www.secniche.org/gds</p>
<p>*Links:*<br />
http://secniche.org/gcrds.html<br />
http://evilfingers.com/advisory/Google_Chrome_Carriage_Return_Null_Objec<br />
t_Memory_Exhaustion_Remote_Dos.php</p>
<p>*Detection:*<br />
SecNiche confirmed this vulnerability affects Google Chrome on Microsoft<br />
Windows XP SP2 platform.The versions tested are:</p>
<p>Chrome/0.2.149.30<br />
Chrome/0.2.149.291</p>
<p>*Disclosure Timeline:*<br />
Disclosed: 22 September 2008<br />
Release Date. September 24 ,2008</p>
<p>*Vendor Response:*<br />
Google acknowledges this vulnerability and &#8220;fix&#8221; will be released soon.</p>
<p>*Credit:*<br />
Aditya K Sood</p>
<p>*Disclaimer*<br />
The information in the advisory is believed to be accurate at the time<br />
of publishing based on<br />
currently available information. Use of the information constitutes<br />
acceptance for use in an<br />
AS IS condition. There is no representation or warranties, either<br />
express or implied by or with<br />
respect to anything in this document, and shall not be liable for a ny<br />
implied warranties of<br />
merchantability or fitness for a particular purpose or for any indirect<br />
special or consequential<br />
damages.</p></blockquote>
<p><a href="http://www.securityfocus.com/archive/1/496688">via securityfocus</a>  </p>
<p>Brought to you by: <a href="http://chrome-hacks.net">Google Chrome Hacks Tips Blog</a></p>
<p><a href="http://chrome-hacks.net/2008/06/25/chrome-security-alert-carriage-return-null-object-memory-exhaustion-remote-dos/">Chrome Security Alert &#8211; Carriage Return Null Object Memory Exhaustion Remote Dos</a></p>

	Tags:<a href="http://chrome-hacks.net/tag/carriage-return/" title="carriage return" rel="tag">carriage return</a>, <a href="http://chrome-hacks.net/category/chrome-security-flawsbugs/" title="Chrome Security Flaws/Bugs" rel="tag">Chrome Security Flaws/Bugs</a>, <a href="http://chrome-hacks.net/tag/denial-of-service/" title="denial of service" rel="tag">denial of service</a>, <a href="http://chrome-hacks.net/tag/dos-version/" title="dos version" rel="tag">dos version</a>, <a href="http://chrome-hacks.net/tag/google/" title="google" rel="tag">google</a>, <a href="http://chrome-hacks.net/tag/javascript-function/" title="javascript function" rel="tag">javascript function</a>, <a href="http://chrome-hacks.net/tag/memory-exhaustion/" title="memory exhaustion" rel="tag">memory exhaustion</a>, <a href="http://chrome-hacks.net/tag/memory-leak-problem/" title="memory leak problem" rel="tag">memory leak problem</a>, <a href="http://chrome-hacks.net/tag/memory-usage/" title="memory usage" rel="tag">memory usage</a>, <a href="http://chrome-hacks.net/tag/null-object/" title="null object" rel="tag">null object</a>, <a href="http://chrome-hacks.net/tag/object-memory/" title="object memory" rel="tag">object memory</a>, <a href="http://chrome-hacks.net/tag/pop-ups/" title="pop ups" rel="tag">pop ups</a>, <a href="http://chrome-hacks.net/tag/proof-of-concept/" title="proof of concept" rel="tag">proof of concept</a>, <a href="http://chrome-hacks.net/tag/resultant-system/" title="resultant system" rel="tag">resultant system</a>, <a href="http://chrome-hacks.net/tag/security-alert/" title="security alert" rel="tag">security alert</a>, <a href="http://chrome-hacks.net/tag/sood/" title="sood" rel="tag">sood</a>, <a href="http://chrome-hacks.net/tag/task-manager/" title="task manager" rel="tag">task manager</a>, <a href="http://chrome-hacks.net/tag/time-user/" title="time user" rel="tag">time user</a>, <a href="http://chrome-hacks.net/tag/vulnerability/" title="vulnerability" rel="tag">vulnerability</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://chrome-hacks.net/2008/06/06/more-chrome-security-flaws/" title="More Chrome Security Flaws (June 6, 2008)">More Chrome Security Flaws</a> </li>
	<li><a href="http://chrome-hacks.net/2008/06/03/google-chrome-has-its-own-task-manager/" title="Google Chrome has its own &amp;quot;Task Manager&amp;quot;! (June 3, 2008)">Google Chrome has its own &amp;quot;Task Manager&amp;quot;!</a> </li>
	<li><a href="http://chrome-hacks.net/2008/06/09/xchrome-beta-version-5-is-a-google-chrome-theme-managerswitcher/" title="XChrome Beta Version 5 is a Google Chrome Theme Manager/Switcher! (June 9, 2008)">XChrome Beta Version 5 is a Google Chrome Theme Manager/Switcher!</a> </li>
	<li><a href="http://chrome-hacks.net/2008/06/03/why-did-google-name-their-browser-chrome/" title="Why did Google name their Browser &amp;quot;Chrome&amp;quot;? (June 3, 2008)">Why did Google name their Browser &amp;quot;Chrome&amp;quot;?</a> </li>
	<li><a href="http://chrome-hacks.net/2008/06/04/what-is-google-chrome-built-on/" title="What is Google Chrome Built On? (June 4, 2008)">What is Google Chrome Built On?</a> </li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://chrome-hacks.net/2008/06/25/chrome-security-alert-carriage-return-null-object-memory-exhaustion-remote-dos/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More Chrome Security Flaws</title>
		<link>http://chrome-hacks.net/2008/06/06/more-chrome-security-flaws/</link>
		<comments>http://chrome-hacks.net/2008/06/06/more-chrome-security-flaws/#comments</comments>
		<pubDate>Fri, 06 Jun 2008 22:51:42 +0000</pubDate>
		<dc:creator>Max</dc:creator>
				<category><![CDATA[Chrome Security Flaws/Bugs]]></category>
		<category><![CDATA[bach khoa]]></category>
		<category><![CDATA[bkis]]></category>
		<category><![CDATA[buffer overflow vulnerability]]></category>
		<category><![CDATA[bugs]]></category>
		<category><![CDATA[complete control]]></category>
		<category><![CDATA[crash]]></category>
		<category><![CDATA[crashes]]></category>
		<category><![CDATA[ebp]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[internet security]]></category>
		<category><![CDATA[little bug]]></category>
		<category><![CDATA[message window]]></category>
		<category><![CDATA[proof of concept]]></category>
		<category><![CDATA[security company]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[security flaws]]></category>

		<guid isPermaLink="false">http://chrome-hacks.net/?p=93</guid>
		<description><![CDATA[
Since Google Chrome is still officially, &#8220;beta&#8221;, there will be a lot of security flaws and bugs that need to be fixed.
I heard about a security flaw where users are not promoted before downloading last week and Google has fixed it but here&#8217;s another one found by a company:
Vietnamese security company Bach Khoa Internet Security [...]]]></description>
			<content:encoded><![CDATA[
<p>Since Google Chrome is still officially, &#8220;beta&#8221;, there will be a lot of security flaws and bugs that need to be fixed.</p>
<p>I heard about a <a href="http://www.readwriteweb.com/archives/security_flaw_in_google_chrome.php">security flaw where users are not promoted before downloading last week</a> and Google has fixed it but here&#8217;s another one found by a company:</p>
<blockquote><p><span id="articleBody">Vietnamese security company <a href="http://security.bkis.vn/">Bach Khoa Internet Security (BKIS)</a> has found a flaw in <a href="http://www.techweb.com/encyclopedia/defineterm.jhtml?term=Google&amp;x=&amp;y=">Google</a> Chrome 0.2.149.27 and posted details on its Web site. The company says the problem is a critical buffer-overflow vulnerability that could allow a <a href="http://www.techweb.com/encyclopedia/defineterm.jhtml?term=hacker&amp;x=&amp;y=">hacker</a> to perform a remote attack and take complete control of the affected system.</span></p></blockquote>
<p>Here&#8217;s the <a href="http://evilfingers.com/advisory/google_chrome_poc.php">proof of concept code</a>:</p>
<blockquote><p>An issue exists in how chrome behaves with undefined-handlers in chrome.dll version 0.2.149.27. A crash can result without user interaction. When a user is made to visit a malicious link, which has an undefined handler followed by a &#8217;special&#8217; character, the chrome crashes with a Google Chrome message window &#8220;Whoa! Google Chrome has crashed. Restart now?&#8221;. It crashes on &#8220;int 3&#8243; at 0&#215;01002FF3 as an exception/trap, followed by &#8220;POP EBP&#8221; instruction when pointed out by the EIP register at 0&#215;01002FF4.</p></blockquote>
<p>I am sure Google will get this little bug fixed real soon but in the meanwhile, you can send any bugs you find to: tips [at] chrome-hacks.net.</p>
<p>via <a href="http://www.informationweek.com/news/internet/google/showArticle.jhtml?articleID=210500290">informationweek</a></p>
<p>Brought to you by: <a href="http://chrome-hacks.net">Google Chrome Hacks Tips Blog</a></p>
<p><a href="http://chrome-hacks.net/2008/06/06/more-chrome-security-flaws/">More Chrome Security Flaws</a></p>

	Tags:<a href="http://chrome-hacks.net/tag/bach-khoa/" title="bach khoa" rel="tag">bach khoa</a>, <a href="http://chrome-hacks.net/tag/bkis/" title="bkis" rel="tag">bkis</a>, <a href="http://chrome-hacks.net/tag/buffer-overflow-vulnerability/" title="buffer overflow vulnerability" rel="tag">buffer overflow vulnerability</a>, <a href="http://chrome-hacks.net/tag/bugs/" title="bugs" rel="tag">bugs</a>, <a href="http://chrome-hacks.net/category/chrome-security-flawsbugs/" title="Chrome Security Flaws/Bugs" rel="tag">Chrome Security Flaws/Bugs</a>, <a href="http://chrome-hacks.net/tag/complete-control/" title="complete control" rel="tag">complete control</a>, <a href="http://chrome-hacks.net/tag/crash/" title="crash" rel="tag">crash</a>, <a href="http://chrome-hacks.net/tag/crashes/" title="crashes" rel="tag">crashes</a>, <a href="http://chrome-hacks.net/tag/ebp/" title="ebp" rel="tag">ebp</a>, <a href="http://chrome-hacks.net/tag/google/" title="google" rel="tag">google</a>, <a href="http://chrome-hacks.net/tag/hacker/" title="hacker" rel="tag">hacker</a>, <a href="http://chrome-hacks.net/tag/hacks/" title="hacks" rel="tag">hacks</a>, <a href="http://chrome-hacks.net/tag/internet-security/" title="internet security" rel="tag">internet security</a>, <a href="http://chrome-hacks.net/tag/little-bug/" title="little bug" rel="tag">little bug</a>, <a href="http://chrome-hacks.net/tag/message-window/" title="message window" rel="tag">message window</a>, <a href="http://chrome-hacks.net/tag/proof-of-concept/" title="proof of concept" rel="tag">proof of concept</a>, <a href="http://chrome-hacks.net/tag/security-company/" title="security company" rel="tag">security company</a>, <a href="http://chrome-hacks.net/tag/security-flaw/" title="security flaw" rel="tag">security flaw</a>, <a href="http://chrome-hacks.net/tag/security-flaws/" title="security flaws" rel="tag">security flaws</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://chrome-hacks.net/2008/06/03/google-chrome-hack-3d-pipe-screensaver-and-more/" title="Google Chrome Hack &#8211; 3D Pipe Screensaver and more! (June 3, 2008)">Google Chrome Hack &#8211; 3D Pipe Screensaver and more!</a> </li>
	<li><a href="http://chrome-hacks.net/2008/06/14/weekly-re-cap-of-google-chrome-tips-and-hacks/" title="Weekly Re-cap of Google Chrome Tips and Hacks! (June 14, 2008)">Weekly Re-cap of Google Chrome Tips and Hacks!</a> </li>
	<li><a href="http://chrome-hacks.net/tip-us/" title="Tip Us! (June 3, 2008)">Tip Us!</a> </li>
	<li><a href="http://chrome-hacks.net/2008/06/11/google-chrome-still-leads-over-50-at-google-chrome-hacks-blog/" title="Google Chrome Still Leads over 50% at Google Chrome Hacks Blog! (June 11, 2008)">Google Chrome Still Leads over 50% at Google Chrome Hacks Blog!</a> </li>
	<li><a href="http://chrome-hacks.net/2008/06/03/google-chrome-launched-with-multi-threading-technology/" title="Google Chrome Launched with Multi-Threading Technology! (June 3, 2008)">Google Chrome Launched with Multi-Threading Technology!</a> </li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://chrome-hacks.net/2008/06/06/more-chrome-security-flaws/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->
