CVE-2019-13707
published 2019-11-25CVE-2019-13707: Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local attacker to leak files via a crafted…
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.45%
36.8th percentile
Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local attacker to leak files via a crafted application.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| chromium | chromium | >= 0 < 78.0.3904.87-1 | 78.0.3904.87-1 |
| debian | chromium | < chromium 78.0.3904.87-1 (bookworm) | chromium 78.0.3904.87-1 (bookworm) |
| chrome | < 78.0.3904.70 | 78.0.3904.70 | |
| chrome | >= unspecified < 78.0.3904.70 | 78.0.3904.70 | |
| chrome_chrome | — | — | |
| opensuse | backports | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-79jw-wrqv-5vh6: Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78
ghsa_unreviewed·2022-05-24
CVE-2019-13707 [MEDIUM] CWE-20 GHSA-79jw-wrqv-5vh6: Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78
Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local attacker to leak files via a crafted application.
OSV
CVE-2019-13707: Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78
osv·2019-11-25·CVSS 5.5
CVE-2019-13707 [MEDIUM] CVE-2019-13707: Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78
Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local attacker to leak files via a crafted application.
Chrome
Stable Channel Update for Desktop: CVE-2019-13707
vendor_chrome·2019-10-22·CVSS 5.5
CVE-2019-13707 [MEDIUM] Stable Channel Update for Desktop: CVE-2019-13707
Stable Channel Update for Desktop
CVE-2019-13707: File storage disclosure. Reported by Andrea Palazzo on 2018-07-01
[$1000][ 931894 ] Medium CVE-2019-13708: HTTP authentication spoof
Reported by Khalil Zhani on 2019-02-13
Severity: medium
Red Hat
chromium-browser: File storage disclosure
vendor_redhat·2019-10-22·CVSS 5.5
CVE-2019-13707 [MEDIUM] chromium-browser: File storage disclosure
chromium-browser: File storage disclosure
Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local attacker to leak files via a crafted application.
Debian
CVE-2019-13707: chromium - Insufficient validation of untrusted input in intents in Google Chrome on Androi...
vendor_debian·2019·CVSS 5.5
CVE-2019-13707 [MEDIUM] CVE-2019-13707: chromium - Insufficient validation of untrusted input in intents in Google Chrome on Androi...
Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local attacker to leak files via a crafted application.
Scope: local
bookworm: resolved (fixed in 78.0.3904.87-1)
bullseye: resolved (fixed in 78.0.3904.87-1)
forky: resolved (fixed in 78.0.3904.87-1)
sid: resolved (fixed in 78.0.3904.87-1)
trixie: resolved (fixed in 78.0.3904.87-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-13699 CVE-2019-13700 CVE-2019-13701 CVE-2019-13702 CVE-2019-13703 CVE-2019-13704 CVE-2019-13705 CVE-2019-13706 CVE-2019-13707 CVE-2019-13708 CVE-2019-13709 CVE-2019-13710 CVE-2019-13711 CVE-2
bugzilla·2019-10-23·CVSS 8.8
CVE-2019-13699 [HIGH] CVE-2019-13699 CVE-2019-13700 CVE-2019-13701 CVE-2019-13702 CVE-2019-13703 CVE-2019-13704 CVE-2019-13705 CVE-2019-13706 CVE-2019-13707 CVE-2019-13708 CVE-2019-13709 CVE-2019-13710 CVE-2019-13711 CVE-2
CVE-2019-13699 CVE-2019-13700 CVE-2019-13701 CVE-2019-13702 CVE-2019-13703 CVE-2019-13704 CVE-2019-13705 CVE-2019-13706 CVE-2019-13707 CVE-2019-13708 CVE-2019-13709 CVE-2019-13710 CVE-2019-13711 CVE-2019-13713 ... chromium: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-l
Bugzilla
CVE-2019-13699 CVE-2019-13700 CVE-2019-13701 CVE-2019-13702 CVE-2019-13703 CVE-2019-13704 CVE-2019-13705 CVE-2019-13706 CVE-2019-13707 CVE-2019-13708 CVE-2019-13709 CVE-2019-13710 CVE-2019-13711 CVE-2
bugzilla·2019-10-23·CVSS 8.8
CVE-2019-13699 [HIGH] CVE-2019-13699 CVE-2019-13700 CVE-2019-13701 CVE-2019-13702 CVE-2019-13703 CVE-2019-13704 CVE-2019-13705 CVE-2019-13706 CVE-2019-13707 CVE-2019-13708 CVE-2019-13709 CVE-2019-13710 CVE-2019-13711 CVE-2
CVE-2019-13699 CVE-2019-13700 CVE-2019-13701 CVE-2019-13702 CVE-2019-13703 CVE-2019-13704 CVE-2019-13705 CVE-2019-13706 CVE-2019-13707 CVE-2019-13708 CVE-2019-13709 CVE-2019-13710 CVE-2019-13711 CVE-2019-13713 ... chromium: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the releva
Bugzilla
CVE-2019-13707 chromium-browser: File storage disclosure
bugzilla·2019-10-23·CVSS 5.5
CVE-2019-13707 [MEDIUM] CVE-2019-13707 chromium-browser: File storage disclosure
CVE-2019-13707 chromium-browser: File storage disclosure
The following flaw was identified in the Chromium browser: File storage disclosure.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=859349
External References:
https://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_22.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1764778]
Affects: fedora-all [bug 1764777]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2019:3759 https://access.redhat.com/errata/RHSA-2019:3759
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-13707
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00008.htmlhttps://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_22.htmlhttps://crbug.com/859349http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00008.htmlhttps://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_22.htmlhttps://crbug.com/859349
2019-11-25
Published