PT-2019-1699 · Google+3 · Google Chrome+3
Jnghwan Kang
+1
·
Publicado
2019-01-30
·
Atualizado
2024-06-15
·
CVE-2019-5774
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 72.0.3626.81
Description
The issue is related to the omission of the .desktop filetype from the Safe Browsing checklist in Google Chrome on Linux. This allowed an attacker, who convinced a user to download a .desktop file, to execute arbitrary code via the downloaded file. The exploitation of this issue may enable a remote attacker to load a .desktop file for executing arbitrary code.
Recommendations
For versions prior to 72.0.3626.81, update to version 72.0.3626.81 or later to resolve the issue. As a temporary workaround, consider avoiding the download of .desktop files from untrusted sources until the update is applied. Restrict access to the SafeBrowsing feature in Google Chrome on Linux to minimize the risk of exploitation.
Exploit
Correção
Missing Authorization
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Google Chrome
Red Hat
Suse