CVE-2019-5771Google Chrome vulnerability

6 documents6 sources
Severity
8.8HIGHNVD
EPSS
1.4%
top 19.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 19
Latest updateMay 13

Description

An incorrect JIT of GLSL shaders in SwiftShader in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages5 packages

CVEListV5google/chromeunspecified72.0.3626.81
NVDgoogle/chrome< 72.0.3626.81

Also affects: Fedora 29, 30

🔴Vulnerability Details

2
GHSA
GHSA-gcw3-m4fx-w329: An incorrect JIT of GLSL shaders in SwiftShader in Google Chrome prior to 722022-05-13
CVEList
CVE-2019-5771: An incorrect JIT of GLSL shaders in SwiftShader in Google Chrome prior to 722019-02-19

📋Vendor Advisories

2
Red Hat
chromium-browser: Heap buffer overflow in SwiftShader2019-01-29
Debian
CVE-2019-5771: chromium - An incorrect JIT of GLSL shaders in SwiftShader in Google Chrome prior to 72.0.3...2019

💬Community

1
Bugzilla
CVE-2019-5771 chromium-browser: Heap buffer overflow in SwiftShader2019-01-30
CVE-2019-5771 — Google Chrome vulnerability | cvebase