CVE-2019-13722
published 2020-01-14CVE-2019-13722: Inappropriate implementation in WebRTC in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted…
PriorityP428medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
1.00%
59.4th percentile
Inappropriate implementation in WebRTC in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| debian | firefox-esr | — | — |
| debian | thunderbird | — | — |
| chrome | < 79.0.3945.79 | 79.0.3945.79 | |
| chrome | >= unspecified < 79.0.3945.79 | 79.0.3945.79 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4q6j-2cv9-cmqj: Inappropriate implementation in WebRTC in Google Chrome prior to 79
ghsa_unreviewed·2022-05-24
CVE-2019-13722 [MEDIUM] GHSA-4q6j-2cv9-cmqj: Inappropriate implementation in WebRTC in Google Chrome prior to 79
Inappropriate implementation in WebRTC in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
OSV
CVE-2019-13722: Inappropriate implementation in WebRTC in Google Chrome prior to 79
osv·2020-01-14·CVSS 6.5
CVE-2019-13722 [MEDIUM] CVE-2019-13722: Inappropriate implementation in WebRTC in Google Chrome prior to 79
Inappropriate implementation in WebRTC in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
Mozilla: Stack corruption due to incorrect number of arguments in WebRTC code
vendor_redhat·2019-12-03·CVSS 6.5
CVE-2019-13722 [MEDIUM] CWE-628 Mozilla: Stack corruption due to incorrect number of arguments in WebRTC code
Mozilla: Stack corruption due to incorrect number of arguments in WebRTC code
Inappropriate implementation in WebRTC in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 5) - Out of support scope
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 7) - Not affected
Package: firefox (Red Hat Enterprise Linux 8) - Not affected
Package: thunderbird (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2019-13722: firefox - Inappropriate implementation in WebRTC in Google Chrome prior to 79.0.3945.79 al...
vendor_debian·2019·CVSS 6.5
CVE-2019-13722 [MEDIUM] CVE-2019-13722: firefox - Inappropriate implementation in WebRTC in Google Chrome prior to 79.0.3945.79 al...
Inappropriate implementation in WebRTC in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
sid: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-13722 Mozilla: Stack corruption due to incorrect number of arguments in WebRTC code
bugzilla·2019-12-04·CVSS 6.5
CVE-2019-13722 [MEDIUM] CVE-2019-13722 Mozilla: Stack corruption due to incorrect number of arguments in WebRTC code
CVE-2019-13722 Mozilla: Stack corruption due to incorrect number of arguments in WebRTC code
When setting a thread name on Windows in WebRTC, an incorrect number of arguments could have been supplied, leading to stack corruption and a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-37/#CVE-2019-13722
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Alexandru Michis
Bugzilla
Intermittent AddressSanitizer: stack-buffer-overflow Z:\task_1567613406\fetches\llvm-project\llvm\projects\compiler-rt\lib\sanitizer_common\sanitizer_common_interceptors.inc:785 in __asan_wrap_memmove
bugzilla·2019-09-10
[MEDIUM] Intermittent AddressSanitizer: stack-buffer-overflow Z:\task_1567613406\fetches\llvm-project\llvm\projects\compiler-rt\lib\sanitizer_common\sanitizer_common_interceptors.inc:785 in __asan_wrap_memmove
Intermittent AddressSanitizer: stack-buffer-overflow Z:\task_1567613406\fetches\llvm-project\llvm\projects\compiler-rt\lib\sanitizer_common\sanitizer_common_interceptors.inc:785 in __asan_wrap_memmove
Failure log:
https://treeherder.mozilla.org/logviewer.html#/jobs?job_id=265898248&repo=mozilla-central&lineNumber=5970
```
[task 2019-09-10T11:25:31.124Z] 11:25:31 INFO - REFTEST TEST-END | file:///Z:/task_1568114275/build/tests/reftest/tests/dom/media/tests/crashtests/837324.html
[task 2019-09-10T11:25:31.142Z] 11:25:31 INFO - [Child 2848: Main Thread]: I/signaling [main|PeerConnectionImpl] PeerConnectionImpl.cpp:2169: CloseInt: Closing PeerConnectionImpl 5475ce64d06cefb1; ending call
[task 2019-09-10T11:25:31.142Z] 11:25:31 INFO - [Child 2848: Main Thread]: I/jsep [1568114731112000 (id=214
2020-01-14
Published