CVE-2019-5785: Stack buffer overflow in Skia
An integer overflow vulnerability in the Skia library can occur after specific transform operations, leading to a potentially exploitable crash.
Other sources
Incorrect convexity calculations in Skia in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
— Launchpad
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/firefox ESRto a version that resolves this vulnerability.Fixed in 60.5.1 - Upgrade
Upgrade
redhat/firefoxto a version that resolves this vulnerability.Fixed in 65.0.1 - Upgrade
Upgrade
redhat/thunderbirdto a version that resolves this vulnerability.Fixed in 60.5.1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 60.5.1 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 65.0.1 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 60.5.1 - Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 72.0.3626.81 - Upgrade
Upgrade
debian/firefoxto a version that resolves this vulnerability.Fixed in 152.0-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 140.11.0esr-1~deb11u1Fixed in 140.10.2esr-1~deb12u1Fixed in 140.12.0esr-1~deb12u1Fixed in 140.10.2esr-1~deb13u1Fixed in 140.12.0esr-1~deb13u1Fixed in 140.11.0esr-1Fixed in 140.12.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:140.12.0esr-1~deb11u1Fixed in 1:140.10.1esr-1~deb12u1Fixed in 1:140.11.0esr-1~deb12u1Fixed in 1:140.10.1esr-1~deb13u1Fixed in 1:140.11.0esr-1~deb13u1Fixed in 1:140.11.0esr-1Fixed in 1:140.12.0esr-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.11.0esr-1~deb11u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.10.2esr-1~deb12u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.12.0esr-1~deb12u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.10.2esr-1~deb13u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.12.0esr-1~deb13u1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.11.0esr-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 140.12.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.12.0esr-1~deb11u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.10.1esr-1~deb12u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.11.0esr-1~deb12u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.10.1esr-1~deb13u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.11.0esr-1~deb13u1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.11.0esr-1 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:140.12.0esr-1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-18356
- CVE-2019-5785
- CVE-2018-18335
- CVE-2018-18509
- CVE-2018-18511
- CVE-2019-5754
- CVE-2019-5782
- CVE-2019-5755
- CVE-2019-5756
- CVE-2019-5757
- CVE-2019-5758
- CVE-2019-5759
- CVE-2019-5760
- CVE-2019-5761
- CVE-2019-5762
- CVE-2019-5763
- CVE-2019-5764
- CVE-2019-13768
- CVE-2019-5765
- CVE-2019-5766
- CVE-2019-5767
- CVE-2019-5768
- CVE-2019-5769
- CVE-2019-5770
- CVE-2019-5771
- CVE-2019-5772
- CVE-2019-5773
- CVE-2019-5774
- CVE-2019-5775
- CVE-2019-5776
- CVE-2019-5777
- CVE-2018-20073
- CVE-2019-5778
- CVE-2019-5779
- CVE-2019-5780
- CVE-2019-5783
- CVE-2019-5781
- CVE-2019-13684
Frequently Asked Questions
What is CVE-2019-5785?
CVE-2019-5785 is an integer overflow vulnerability in the Skia library that can occur after specific transform operations in Google Chrome prior to 72.0.3626.81.
How severe is CVE-2019-5785?
CVE-2019-5785 has a severity rating of 6.5, which is considered high.
What software is affected by CVE-2019-5785?
CVE-2019-5785 affects Google Chrome prior to 72.0.3626.81, Mozilla Firefox versions up to 65.0.1, and Mozilla Firefox ESR versions up to 60.5.1.
How can I fix CVE-2019-5785?
To fix CVE-2019-5785, update your software to Google Chrome version 72.0.3626.81 or later, Mozilla Firefox version 65.0.1 or later, or Mozilla Firefox ESR version 60.5.1 or later.
Where can I find more information about CVE-2019-5785?
You can find more information about CVE-2019-5785 on the following websites: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1525433), [Google Project Zero Blog](https://googleprojectzero.blogspot.com/2019/02/the-curious-case-of-convexity-confusion.html), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2019-05/).