PT-2019-2888 · Google+8 · Google Chrome+8

Mlfbrown

·

Publicado

2019-04-12

·

Atualizado

2024-06-15

·

CVE-2019-5827

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 74.0.3729.131
Description The issue is related to an integer overflow in SQLite via WebSQL, which can be exploited by a remote attacker using a specially crafted HTML page. This could potentially lead to heap corruption, affecting the confidentiality, integrity, and availability of protected information.
Recommendations For versions prior to 74.0.3729.131, update to version 74.0.3729.131 or later to resolve the issue. As a temporary workaround, consider restricting access to WebSQL in Google Chrome until the update is applied.

Exploit

Correção

Memory Corruption

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2021:4396
ALT-PU-2019-1782
BDU:2019-02857
CESA-2021_4396
CVE-2019-5827
DLA-2340-1
DSA-4500-1
MGASA-2019-0283
OPENSUSE-SU-2019:1456-1
OPENSUSE-SU-2019:1488-1
OPENSUSE-SU-2019:1666-1
OPENSUSE-SU-2019_1456-1
OPENSUSE-SU-2019_1666-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:12948-1
RHSA-2019:1243
RHSA-2019_1243
RHSA-2021:4396
RHSA-2021_4396
RLSA-2021:4396
USN-4205-1

Produtos afetados

Alt Linux
Almalinux
Centos
Google Chrome
Red Hat
Rocky Linux
Sqlite
Suse
Ubuntu