PT-2019-2888 · Google+8 · Google Chrome+8

Mlfbrown

·

Published

2019-04-12

·

Updated

2024-06-15

·

CVE-2019-5827

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 74.0.3729.131
Description The issue is related to an integer overflow in SQLite via WebSQL, which can be exploited by a remote attacker using a specially crafted HTML page. This could potentially lead to heap corruption, affecting the confidentiality, integrity, and availability of protected information.
Recommendations For versions prior to 74.0.3729.131, update to version 74.0.3729.131 or later to resolve the issue. As a temporary workaround, consider restricting access to WebSQL in Google Chrome until the update is applied.

Exploit

Fix

Memory Corruption

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4396
ALT-PU-2019-1782
BDU:2019-02857
CESA-2021_4396
CVE-2019-5827
DLA-2340-1
DSA-4500-1
MGASA-2019-0283
OPENSUSE-SU-2019:1456-1
OPENSUSE-SU-2019:1488-1
OPENSUSE-SU-2019:1666-1
OPENSUSE-SU-2019_1456-1
OPENSUSE-SU-2019_1666-1
OPENSUSE-SU-2024:10681-1
OPENSUSE-SU-2024:12948-1
RHSA-2019:1243
RHSA-2019_1243
RHSA-2021:4396
RHSA-2021_4396
RLSA-2021:4396
USN-4205-1

Affected Products

Alt Linux
Almalinux
Centos
Google Chrome
Red Hat
Rocky Linux
Sqlite
Suse
Ubuntu