CVE-2019-5788: Use after free in FileAPI
An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.
Other sources
An use after free flaw was found in the FileAPI component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=925864
External References:
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop12.html
— Red Hat
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2019-5788?
CVE-2019-5788 has been classified as a high severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2019-5788?
To fix CVE-2019-5788, update your Google Chrome or Chromium browser to version 73.0.3683.75 or later.
What type of vulnerability is CVE-2019-5788?
CVE-2019-5788 is an integer overflow vulnerability that leads to a use-after-free error.
Which software is affected by CVE-2019-5788?
CVE-2019-5788 affects Google Chrome and Chromium browser versions prior to 73.0.3683.75 on Linux.
Can CVE-2019-5788 be exploited remotely?
Yes, CVE-2019-5788 can be exploited remotely by an attacker through a crafted HTML page.