CVE-2019-5769
published 2019-02-19CVE-2019-5769: Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to…
PriorityP342high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.61%
73.2th percentile
Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 72.0.3626.81-1 | 72.0.3626.81-1 |
| chromium | chromium | >= 0 < 72.0.3626.81-1 | 72.0.3626.81-1 |
| chromium | chromium | >= 0 < 72.0.3626.81-1 | 72.0.3626.81-1 |
| chromium | chromium | >= 0 < 72.0.3626.81-1 | 72.0.3626.81-1 |
| debian | chromium | < chromium 72.0.3626.81-1 (bookworm) | chromium 72.0.3626.81-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | < 72.0.3626.81 | 72.0.3626.81 | |
| chrome | >= unspecified < 72.0.3626.81 | 72.0.3626.81 | |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: Insufficient validation of untrusted input in Blink
vendor_redhat·2019-01-29·CVSS 8.8
CVE-2019-5769 [HIGH] chromium-browser: Insufficient validation of untrusted input in Blink
chromium-browser: Insufficient validation of untrusted input in Blink
Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Debian
CVE-2019-5769: chromium - Incorrect handling of invalid end character position when front rendering in Bli...
vendor_debian·2019·CVSS 8.8
CVE-2019-5769 [HIGH] CVE-2019-5769: chromium - Incorrect handling of invalid end character position when front rendering in Bli...
Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 72.0.3626.81-1)
bullseye: resolved (fixed in 72.0.3626.81-1)
forky: resolved (fixed in 72.0.3626.81-1)
sid: resolved (fixed in 72.0.3626.81-1)
trixie: resolved (fixed in 72.0.3626.81-1)
GHSA
GHSA-6m7c-33xf-693j: Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72
ghsa_unreviewed·2022-05-14
CVE-2019-5769 [HIGH] CWE-20 GHSA-6m7c-33xf-693j: Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72
Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
OSV
CVE-2019-5769: Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72
osv·2019-02-19·CVSS 8.8
CVE-2019-5769 [HIGH] CVE-2019-5769: Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72
Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2019:0309https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.htmlhttps://crbug.com/913975https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JVFHYCJGMZQUKYSIE2BXE4NLEGFGUXU5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQOP53LXXPRGD4N5OBKGQTSMFXT32LF6/https://www.debian.org/security/2019/dsa-4395https://access.redhat.com/errata/RHSA-2019:0309https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.htmlhttps://crbug.com/913975https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JVFHYCJGMZQUKYSIE2BXE4NLEGFGUXU5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQOP53LXXPRGD4N5OBKGQTSMFXT32LF6/https://www.debian.org/security/2019/dsa-4395
2019-02-19
Published