CVE-2019-5772
published 2019-02-19CVE-2019-5772: Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap…
PriorityP342high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.73%
75.0th percentile
Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 72.0.3626.81-1 | 72.0.3626.81-1 |
| chromium | chromium | >= 0 < 72.0.3626.81-1 | 72.0.3626.81-1 |
| chromium | chromium | >= 0 < 72.0.3626.81-1 | 72.0.3626.81-1 |
| chromium | chromium | >= 0 < 72.0.3626.81-1 | 72.0.3626.81-1 |
| debian | chromium | < chromium 72.0.3626.81-1 (bookworm) | chromium 72.0.3626.81-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | < 72.0.3626.81 | 72.0.3626.81 | |
| chrome | >= unspecified < 72.0.3626.81 | 72.0.3626.81 | |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-93g9-45m8-559m: Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72
ghsa_unreviewed·2022-05-13
CVE-2019-5772 [HIGH] CWE-787 GHSA-93g9-45m8-559m: Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72
Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
OSV
CVE-2019-5772: Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72
osv·2019-02-19·CVSS 8.8
CVE-2019-5772 [HIGH] CVE-2019-5772: Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72
Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Red Hat
chromium-browser: Use after free in PDFium
vendor_redhat·2019-01-29·CVSS 8.8
CVE-2019-5772 [HIGH] chromium-browser: Use after free in PDFium
chromium-browser: Use after free in PDFium
Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Debian
CVE-2019-5772: chromium - Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome...
vendor_debian·2019·CVSS 8.8
CVE-2019-5772 [HIGH] CVE-2019-5772: chromium - Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome...
Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Scope: local
bookworm: resolved (fixed in 72.0.3626.81-1)
bullseye: resolved (fixed in 72.0.3626.81-1)
forky: resolved (fixed in 72.0.3626.81-1)
sid: resolved (fixed in 72.0.3626.81-1)
trixie: resolved (fixed in 72.0.3626.81-1)
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/106767https://access.redhat.com/errata/RHSA-2019:0309https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.htmlhttps://crbug.com/908292https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JVFHYCJGMZQUKYSIE2BXE4NLEGFGUXU5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQOP53LXXPRGD4N5OBKGQTSMFXT32LF6/https://www.debian.org/security/2019/dsa-4395http://www.securityfocus.com/bid/106767https://access.redhat.com/errata/RHSA-2019:0309https://chromereleases.googleblog.com/2019/01/stable-channel-update-for-desktop.htmlhttps://crbug.com/908292https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JVFHYCJGMZQUKYSIE2BXE4NLEGFGUXU5/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQOP53LXXPRGD4N5OBKGQTSMFXT32LF6/https://www.debian.org/security/2019/dsa-4395
2019-02-19
Published