First published: Thu Jun 27 2019(Updated: )
Heap buffer overflow in ANGLE in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/chromium | 90.0.4430.212-1~deb10u1 116.0.5845.180-1~deb11u1 120.0.6099.129-1~deb11u1 119.0.6045.199-1~deb12u1 120.0.6099.129-1~deb12u1 120.0.6099.129-1 | |
Google Chrome | <75.0.3770.80 | |
SUSE Backports | =sle-15 | |
openSUSE | =15.0 | |
openSUSE | =15.1 | |
openSUSE | =42.3 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =29 | |
Fedoraproject Fedora | =30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5836 is a vulnerability that allows a remote attacker to potentially exploit heap corruption in ANGLE in Google Chrome prior to version 75.0.3770.80 via a crafted HTML page.
CVE-2019-5836 has a severity score of 8.8 (high severity).
Google Chrome versions prior to 75.0.3770.80, Opensuse Backports sle-15, openSUSE Leap 15.0, openSUSE Leap 15.1, openSUSE Leap 42.3, Debian Debian Linux 10.0, Fedoraproject Fedora 29, Fedoraproject Fedora 30, and chromium versions listed in the reference are affected by CVE-2019-5836.
Update Google Chrome to version 75.0.3770.80 or later, or follow the remedy instructions provided in the reference for Opensuse Backports, openSUSE Leap, Debian Debian Linux, and Fedoraproject Fedora.
You can find more information about CVE-2019-5836 at the references provided: http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00085.html, https://chromereleases.googleblog.com/2019/06/stable-channel-update-for-desktop.html, https://crbug.com/947342