PT-2019-2888 · Google+8 · Google Chrome+8
Mlfbrown
·
Publicado
2019-04-12
·
Atualizado
2024-06-15
·
CVE-2019-5827
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 74.0.3729.131
Description
The issue is related to an integer overflow in SQLite via WebSQL, which can be exploited by a remote attacker using a specially crafted HTML page. This could potentially lead to heap corruption, affecting the confidentiality, integrity, and availability of protected information.
Recommendations
For versions prior to 74.0.3729.131, update to version 74.0.3729.131 or later to resolve the issue. As a temporary workaround, consider restricting access to WebSQL in Google Chrome until the update is applied.
Exploit
Correção
Memory Corruption
Integer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Almalinux
Centos
Google Chrome
Red Hat
Rocky Linux
Sqlite
Suse
Ubuntu