News Category

New & Updates

1.South Korea's free computer game model hits US

2.Apple Threatens To Close iTunes Store If Fee Hiked

3.Men happiest online, women prefer family time: poll

4.Congress targets rogue online pharmacies

5.Best Buy gets antitrust approval to buy Napster

6.Netflix adds Starz power to online catalogue

7.Internet Radio Bill Advances To White House

8.Congress passes bill to help save Internet radio

9.British band Oasis launching new album on MySpace

10.StumbleUpon Without Tripping on a Toolbar

Highest Hits 10

1.New languages crack Roman alphabet's Internet address dominance

2.FCC eases some broadband rules on AT&T

3.House panel votes to extend Net tax ban

4.Spears label files Web piracy suit

5.Press group slams Chinese online censorship

6.Blogger preaches Internet download freedoms

7.Italy launches auction for WiMAX licenses

8.Future may be murky for Yahoo and newspaper alliance

9.Chinese Internet Censorship Machine Revealed

10.YouTube lets users map videos onto Google Earth

Security firm spots Chrome 'SaveAs' flaw


It's been only a few days since Google released its Chrome browser, and security researchers are still digging into the software in search of the first few flaws.

A company in Vietnam has turned up the latest vulnerability in Chrome, according to a story posted to Information Week's Web site. Bach Khoa Internet Security says that the Chrome 0.2.149.27 release is susceptible to a critical buffer-overflow flaw, which could allow a remote attacker to take control of a PC. BKIS says it has reported the vulnerability to Google.

Here's how BKIS describes the vulnerability and how it could be exploited:

The vulnerability is caused due to a boundary error when handling the "SaveAs" function. On saving a malicious page with an overly long title (title tag in HTML), the program causes a stack-based overflow and makes it possible for attackers to execute arbitrary code on users' systems.

To exploit the Vulnerability, a hacker might construct a specially crafted Web page, which contains malicious code. He then tricks users into visiting his Website and convinces them to save this Page. Right after that, the code would be executed, giving him the privilege to make use of the affected system.

Earlier this week, security researcher Rishi Narang reported a flaw related to how Chrome, still in beta, behaves with undefined handlers, while another researcher, Aviv Raff, developed a proof-of-concept demo that showed Chrome could be hit with a carpet-bombing flaw.

Click here for full coverage of the Google Chrome launch.