PT-2019-1699 · Google+3 · Google Chrome+3
Jnghwan Kang
+1
·
Published
2019-01-30
·
Updated
2024-06-15
·
CVE-2019-5774
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 72.0.3626.81
Description
The issue is related to the omission of the .desktop filetype from the Safe Browsing checklist in Google Chrome on Linux. This allowed an attacker, who convinced a user to download a .desktop file, to execute arbitrary code via the downloaded file. The exploitation of this issue may enable a remote attacker to load a .desktop file for executing arbitrary code.
Recommendations
For versions prior to 72.0.3626.81, update to version 72.0.3626.81 or later to resolve the issue. As a temporary workaround, consider avoiding the download of .desktop files from untrusted sources until the update is applied. Restrict access to the SafeBrowsing feature in Google Chrome on Linux to minimize the risk of exploitation.
Exploit
Fix
Missing Authorization
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Google Chrome
Red Hat
Suse