PT-2019-1699 · Google+3 · Google Chrome+3

Jnghwan Kang

+1

·

Published

2019-01-30

·

Updated

2024-06-15

·

CVE-2019-5774

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 72.0.3626.81
Description The issue is related to the omission of the .desktop filetype from the Safe Browsing checklist in Google Chrome on Linux. This allowed an attacker, who convinced a user to download a .desktop file, to execute arbitrary code via the downloaded file. The exploitation of this issue may enable a remote attacker to load a .desktop file for executing arbitrary code.
Recommendations For versions prior to 72.0.3626.81, update to version 72.0.3626.81 or later to resolve the issue. As a temporary workaround, consider avoiding the download of .desktop files from untrusted sources until the update is applied. Restrict access to the SafeBrowsing feature in Google Chrome on Linux to minimize the risk of exploitation.

Exploit

Fix

Missing Authorization

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1257
BDU:2019-01309
CVE-2019-5774
DSA-4395-1
DSA-4395-2
OPENSUSE-SU-2019:0204-1
OPENSUSE-SU-2019:0206-1
OPENSUSE-SU-2019:0216-1
OPENSUSE-SU-2019_0204-1
OPENSUSE-SU-2019_0205-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:12948-1
RHSA-2019:0309
RHSA-2019_0309

Affected Products

Alt Linux
Google Chrome
Red Hat
Suse