CVE-2019-5774: Insufficient validation of untrusted input in SafeBrowsing
An insufficient validation of untrusted input flaw was found in the SafeBrowsing component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=904182
External References:
https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.html
Other sources
Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsing in Google Chrome on Linux prior to 72.0.3626.81 allowed an attacker who convinced a user to download a .desktop file to execute arbitrary code via a downloaded .desktop file.
Credit
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-5754
- CVE-2019-5782
- CVE-2019-5755
- CVE-2019-5756
- CVE-2019-5757
- CVE-2019-5758
- CVE-2019-5759
- CVE-2019-5760
- CVE-2019-5761
- CVE-2019-5762
- CVE-2019-5763
- CVE-2019-5764
- CVE-2019-13768
- CVE-2019-5765
- CVE-2019-5785
- CVE-2019-5766
- CVE-2019-5767
- CVE-2019-5768
- CVE-2019-5769
- CVE-2019-5770
- CVE-2019-5771
- CVE-2019-5772
- CVE-2019-5773
- CVE-2019-5775
- CVE-2019-5776
- CVE-2019-5777
- CVE-2018-20073
- CVE-2019-5778
- CVE-2019-5779
- CVE-2019-5780
- CVE-2019-5783
- CVE-2019-5781
- CVE-2019-13684
Frequently Asked Questions
What is the severity of CVE-2019-5774?
CVE-2019-5774 is classified as a high-severity vulnerability due to insufficient validation of untrusted input in the SafeBrowsing component of Chromium.
How do I fix CVE-2019-5774?
To fix CVE-2019-5774, users should update to the latest versions of Chrome or Chromium specified in the vulnerability report.
Which versions are affected by CVE-2019-5774?
CVE-2019-5774 affects Chrome versions prior to 72.0.3626.81 and several versions of Chromium on Debian and Red Hat Linux.
Are there specific platforms impacted by CVE-2019-5774?
CVE-2019-5774 impacts users on Debian, Red Hat, and Fedora platforms running vulnerable versions of Chrome and Chromium.
What should I do if I cannot update my browser to mitigate CVE-2019-5774?
If updating is not possible, consider using alternative browsers with better security until a resolution can be implemented.