-----BEGIN PGP SIGNED MESSAGE-----
AUSCERT Security Bulletin
A number of vulnerabilities have been identified in Google Chrome
10 July 2013
AusCERT Security Bulletin Summary
Product: Google Chrome
Operating System: Windows
Impact/Access: Execute Arbitrary Code/Commands -- Remote with User Interaction
Denial of Service -- Remote with User Interaction
Provide Misleading Information -- Remote with User Interaction
Unauthorised Access -- Remote with User Interaction
Reduced Security -- Remote with User Interaction
Member content until: Friday, August 9 2013
Vulnerabilities have been identified in Google Chrome prior to version
28.0.1500.71 for Windows, Mac and Chrome Frame platforms. 
Google has provided the following details regarding these issues:
"[$21,500] A special reward for Andrey Labunets for his combination of
CVE-2013-2879 and CVE-2013-2868 along with some (since fixed)
 Low CVE-2013-2867: Block pop-unders in various scenarios.
 High CVE-2013-2879: Confusion setting up sign-in and sync.
Credit to Andrey Labunets.
 Medium CVE-2013-2868: Incorrect sync of NPAPI extension
component. Credit to Andrey Labunets.
 Medium CVE-2013-2869: Out-of-bounds read in JPEG2000 handling.
Credit to Felix Groebert of Google Security Team.
[$6267.4]   Critical CVE-2013-2870: Use-after-free
with network sockets. Credit to Collin Payne.
[$3133.7]  Medium CVE-2013-2853: Man-in-the-middle attack
against HTTP in SSL. Credit to Antoine Delignat-Lavaud and Karthikeyan
Bhargavan from Prosecco at INRIA Paris.
[$2000]   High CVE-2013-2871: Use-after-free in input
handling. Credit to miaubiz.
[Mac only]  Low CVE-2013-2872: Possible lack of entropy in
renderers. Credit to Eric Rescorla.
[$1000]  High CVE-2013-2873: Use-after-free in resource
loading. Credit to miaubiz.
[Windows + NVIDIA only] [$500]  Medium CVE-2013-2874: Screen
data leak with GL textures. Credit to "danguafer".
[$500]  Medium CVE-2013-2875: Out-of-bounds-read in SVG.
Credit to miaubiz.
 Medium CVE-2013-2876: Extensions permissions confusion with
interstitials. Credit to Dev Akhawe.
 Low CVE-2013-2877: Out-of-bounds read in XML parsing. Credit
to Aki Helin of OUSPG.
 None: Remove the "viewsource" attribute on iframes. Credit to
 Medium CVE-2013-2878: Out-of-bounds read in text handling.
Credit to Atte Kettunen of OUSPG.
In addition, our ongoing internal security work was as usual
responsible for a wide range of fixes:
 High CVE-2013-2880: Various fixes from internal audits,
fuzzing and other initiatives (Chrome 28)." 
The vendor recommends updating to the latest version of Google Chrome
to correct these issues. 
 Stable Channel Update
AusCERT has made every effort to ensure that the information contained
in this document is accurate. However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.
Australian Computer Emergency Response Team
The University of Queensland
Internet Email: firstname.lastname@example.org
Facsimile: (07) 3365 7031
Telephone: (07) 3365 4417 (International: +61 7 3365 4417)
AusCERT personnel answer during Queensland business hours
which are GMT+10:00 (AEST).
On call after hours for member emergencies only.
-----BEGIN PGP SIGNATURE-----
-----END PGP SIGNATURE-----