CVE-2019-5759: Use after free in HTML select elements
An use after free flaw was found in the HTML select elements component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=912211
External References:
https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
Other sources
Incorrect lifetime handling in HTML select elements in Google Chrome on Android and Mac prior to 72.0.3626.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-5754
- CVE-2019-5782
- CVE-2019-5755
- CVE-2019-5756
- CVE-2019-5757
- CVE-2019-5758
- CVE-2019-5760
- CVE-2019-5761
- CVE-2019-5762
- CVE-2019-5763
- CVE-2019-5764
- CVE-2019-13768
- CVE-2019-5765
- CVE-2019-5785
- CVE-2019-5766
- CVE-2019-5767
- CVE-2019-5768
- CVE-2019-5769
- CVE-2019-5770
- CVE-2019-5771
- CVE-2019-5772
- CVE-2019-5773
- CVE-2019-5774
- CVE-2019-5775
- CVE-2019-5776
- CVE-2019-5777
- CVE-2018-20073
- CVE-2019-5778
- CVE-2019-5779
- CVE-2019-5780
- CVE-2019-5783
- CVE-2019-5781
- CVE-2019-13684
Frequently Asked Questions
What is the severity of CVE-2019-5759?
CVE-2019-5759 is classified as a high-severity vulnerability due to its potential to cause use-after-free errors in the Chromium browser.
How do I fix CVE-2019-5759?
To fix CVE-2019-5759, update Chromium to version 90.0.4430.212 or later for Debian, or to version 72.0.3626.81 or later for Red Hat systems.
Which versions of Google Chrome are affected by CVE-2019-5759?
Google Chrome versions prior to 72.0.3626.81 are affected by CVE-2019-5759.
Is CVE-2019-5759 present in Apple macOS or Google Android?
No, CVE-2019-5759 does not affect Apple macOS or Google Android.
What is the primary impact of CVE-2019-5759?
The primary impact of CVE-2019-5759 is the potential for attacker-controlled data to be executed leading to crashes or arbitrary code execution.