PT-2019-3424 · Google+3 · Google Chrome+3

Mark Brand

·

Publicado

2019-04-23

·

Atualizado

2024-06-15

·

CVE-2019-5809

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 74.0.3729.108
Description The issue is related to a use after free error in the file chooser of Google Chrome, which can be exploited by a remote attacker who has compromised the renderer process. This can lead to privilege escalation via a crafted HTML page, potentially allowing the attacker to impact data integrity, gain unauthorized access to sensitive information, and cause a denial of service.
Recommendations For Google Chrome versions prior to 74.0.3729.108, update to version 74.0.3729.108 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially malicious HTML pages to minimize the risk of exploitation.

Exploit

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1782
BDU:2019-03581
CVE-2019-5809
DSA-4500-1
MGASA-2019-0283
OPENSUSE-SU-2019:1325-1
OPENSUSE-SU-2019:1436-1
OPENSUSE-SU-2019:1666-1
OPENSUSE-SU-2019_1324-1
OPENSUSE-SU-2019_1325-1
OPENSUSE-SU-2019_1666-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:12948-1
RHSA-2019:1021
RHSA-2019_1021

Produtos afetados

Alt Linux
Google Chrome
Red Hat
Suse