PT-2019-5136 · Google+3 · Google Chrome+3

Sergei Glazunov

·

Publicado

2019-12-17

·

Atualizado

2024-06-15

·

CVE-2019-13767

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 79.0.3945.88
Description The issue is related to a use after free vulnerability in the media picker mechanism of Google Chrome, which can be exploited by a remote attacker who has compromised the renderer process. This can potentially lead to heap corruption via a crafted HTML page, allowing the attacker to gain unauthorized access to confidential data, cause a denial of service, and impact data integrity.
Recommendations For versions prior to 79.0.3945.88, update to version 79.0.3945.88 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially malicious HTML pages to minimize the risk of exploitation.

Correção

Use After Free

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2020-1129
ALT-PU-2020-1171
ALT-PU-2020-1707
ALT-PU-2020-2441
BDU:2020-01803
CVE-2019-13767
DSA-4606-1
MGASA-2020-0078
OPENSUSE-SU-2019:2712-1
OPENSUSE-SU-2019_2712-1
OPENSUSE-SU-2020:0007-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:12948-1
RHSA-2020:0005
RHSA-2020_0005

Produtos afetados

Alt Linux
Google Chrome
Red Hat
Suse