PT-2019-1699 · Google+3 · Google Chrome+3

Jnghwan Kang

+1

·

Publicado

2019-01-30

·

Atualizado

2024-06-15

·

CVE-2019-5774

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 72.0.3626.81
Description The issue is related to the omission of the .desktop filetype from the Safe Browsing checklist in Google Chrome on Linux. This allowed an attacker, who convinced a user to download a .desktop file, to execute arbitrary code via the downloaded file. The exploitation of this issue may enable a remote attacker to load a .desktop file for executing arbitrary code.
Recommendations For versions prior to 72.0.3626.81, update to version 72.0.3626.81 or later to resolve the issue. As a temporary workaround, consider avoiding the download of .desktop files from untrusted sources until the update is applied. Restrict access to the SafeBrowsing feature in Google Chrome on Linux to minimize the risk of exploitation.

Exploit

Correção

Missing Authorization

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1257
BDU:2019-01309
CVE-2019-5774
DSA-4395-1
DSA-4395-2
OPENSUSE-SU-2019:0204-1
OPENSUSE-SU-2019:0206-1
OPENSUSE-SU-2019:0216-1
OPENSUSE-SU-2019_0204-1
OPENSUSE-SU-2019_0205-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:12948-1
RHSA-2019:0309
RHSA-2019_0309

Produtos afetados

Alt Linux
Google Chrome
Red Hat
Suse