CVE-2019-5798: Out of bounds read in Skia
An out of bounds read flaw was found in the Skia component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=883596
External References:
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop12.html
Other sources
An out-of-bounds read can occur in the Skia library during path transformations. This could result in the exposure of data stored in memory.
— Mozilla
Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
— Launchpad
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/chromium-browserto a version that resolves this vulnerability.Fixed in 73.0.3683.75 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 60.7 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 60.7 - Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 73.0.3683.75 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 120.0.6099.224-1~deb11u1Fixed in 150.0.7871.100-1~deb12u1Fixed in 151.0.7922.137-1~deb12u1Fixed in 150.0.7871.100-1~deb13u1Fixed in 151.0.7922.137-1~deb13u1Fixed in 150.0.7871.181-1Fixed in 151.0.7922.137-2 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 140.13.0esr-1~deb11u1Fixed in 140.12.0esr-1~deb12u1Fixed in 140.13.0esr-1~deb12u1Fixed in 140.12.0esr-1~deb13u1Fixed in 140.13.0esr-1~deb13u1Fixed in 140.13.0esr-2 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:140.13.0esr-2~deb11u1Fixed in 1:140.12.0esr-1~deb12u1Fixed in 1:140.13.0esr-2~deb12u1Fixed in 1:140.12.0esr-1~deb13u1Fixed in 1:140.13.0esr-2~deb13u1Fixed in 1:140.13.0esr-2 - Upgrade
Upgrade
Chromium/Google Chrome (Skia component)to a version that resolves this vulnerability.Fixed in 73.0.3683.75
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-9815
- CVE-2019-9816
- CVE-2019-9817
- CVE-2019-9818
- CVE-2019-9819
- CVE-2019-9820
- CVE-2019-11691
- CVE-2019-11692
- CVE-2019-11693
- CVE-2019-7317
- CVE-2019-9797
- CVE-2018-18511
- CVE-2019-11694
- CVE-2019-11698
- CVE-2019-5798
- CVE-2019-9800
- CVE-2019-5787
- CVE-2019-5788
- CVE-2019-5789
- CVE-2019-5790
- CVE-2019-5791
- CVE-2019-5792
- CVE-2019-5793
- CVE-2019-5794
- CVE-2019-5795
- CVE-2019-5796
- CVE-2019-5797
- CVE-2019-5799
- CVE-2019-5800
- CVE-2019-5801
- CVE-2019-5802
- CVE-2019-5803
- CVE-2019-5804
Frequently Asked Questions
What is CVE-2019-5798?
CVE-2019-5798 is a vulnerability in the Skia library in Google Chrome that allows a remote attacker to perform an out-of-bounds memory read.
How severe is CVE-2019-5798?
CVE-2019-5798 has a severity rating of 6.5 out of 10.
Which software is affected by CVE-2019-5798?
CVE-2019-5798 affects Google Chrome prior to version 73.0.3683.75.
How can I fix CVE-2019-5798?
To fix CVE-2019-5798, update Google Chrome to version 73.0.3683.75 or higher.
Where can I find more information about CVE-2019-5798?
You can find more information about CVE-2019-5798 in the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1535518), [Mozilla Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2019-14/), [SecLists](https://seclists.org/bugtraq/2019/May/67).