CVE-2019-5824
published 2019-06-27CVE-2019-5824: Parameter passing error in media in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…
PriorityP341high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.37%
68.9th percentile
Parameter passing error in media in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 75.0.3770.80-1 | 75.0.3770.80-1 |
| chromium | chromium | >= 0 < 75.0.3770.80-1 | 75.0.3770.80-1 |
| chromium | chromium | >= 0 < 75.0.3770.80-1 | 75.0.3770.80-1 |
| chromium | chromium | >= 0 < 75.0.3770.80-1 | 75.0.3770.80-1 |
| debian | chromium | < chromium 75.0.3770.80-1 (bookworm) | chromium 75.0.3770.80-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | < 74.0.3729.131 | 74.0.3729.131 | |
| chrome | >= unspecified < 74.0.3729.131 | 74.0.3729.131 | |
| mozilla | thunderbird | >= 0 < 1:60.5.1+build2-0ubuntu0.14.04.1 | 1:60.5.1+build2-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:60.5.1+build2-0ubuntu0.16.04.1 | 1:60.5.1+build2-0ubuntu0.16.04.1 |
| mozilla | thunderbird | >= 0 < 1:60.5.1+build2-0ubuntu0.18.04.1 | 1:60.5.1+build2-0ubuntu0.18.04.1 |
| opensuse | backports | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cgrx-cg2f-3whx: Parameter passing error in media in Google Chrome prior to 74
ghsa_unreviewed·2022-05-24
CVE-2019-5824 [HIGH] CWE-787 GHSA-cgrx-cg2f-3whx: Parameter passing error in media in Google Chrome prior to 74
Parameter passing error in media in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
OSV
CVE-2019-5824: Parameter passing error in media in Google Chrome prior to 74
osv·2019-06-27·CVSS 8.8
CVE-2019-5824 [HIGH] CVE-2019-5824: Parameter passing error in media in Google Chrome prior to 74
Parameter passing error in media in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
OSV
thunderbird vulnerabilities
osv·2019-02-26·CVSS 5.5
CVE-2016-5824 thunderbird vulnerabilities
thunderbird vulnerabilities
A use-after-free was discovered in libical. If a user were tricked in to
opening a specially crafted ICS calendar file, an attacker could
potentially exploit this to cause a denial of service. (CVE-2016-5824)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted message, an attacker could
potentially exploit these to cause a denial of service, or execute
arbitrary code. (CVE-2018-18356, CVE-2018-18500, CVE-2019-5785)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
gain additional privileges by escaping the sandbox, or execute arbitr
Red Hat
chromium-browser: parameter passing error in media player leading to unauthorized access
vendor_redhat·2019-04-30·CVSS 8.8
CVE-2019-5824 [HIGH] CWE-20 chromium-browser: parameter passing error in media player leading to unauthorized access
chromium-browser: parameter passing error in media player leading to unauthorized access
Parameter passing error in media in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Debian
CVE-2019-5824: chromium - Parameter passing error in media in Google Chrome prior to 74.0.3729.131 allowed...
vendor_debian·2019·CVSS 8.8
CVE-2019-5824 [HIGH] CVE-2019-5824: chromium - Parameter passing error in media in Google Chrome prior to 74.0.3729.131 allowed...
Parameter passing error in media in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 75.0.3770.80-1)
bullseye: resolved (fixed in 75.0.3770.80-1)
forky: resolved (fixed in 75.0.3770.80-1)
sid: resolved (fixed in 75.0.3770.80-1)
trixie: resolved (fixed in 75.0.3770.80-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-5824 chromium-browser: parameter passing error in media player leading to unauthorized access
bugzilla·2019-05-06·CVSS 8.8
CVE-2019-5824 [HIGH] CVE-2019-5824 chromium-browser: parameter passing error in media player leading to unauthorized access
CVE-2019-5824 chromium-browser: parameter passing error in media player leading to unauthorized access
Chrome could allow a remote attacker to bypass security restrictions, caused by a parameter passing error in media player. By persuading a victim to visit a specially-crafted Web site, an attacker could exploit this vulnerability to gain unauthorized access to the system.
External References:
https://exchange.xforce.ibmcloud.com/vulnerabilities/160323
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-7 [bug 1706814]
Affects: fedora-all [bug 1706815]
---
External References:
https://chromereleases.googleblog.com/2019/04/stable-channel-update-for-desktop_30.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Suppleme
Bugzilla
CVE-2019-5824 chromium: chromium-browser: parameter passing error in media player leading to unauthorized access [epel-7]
bugzilla·2019-05-06·CVSS 8.8
CVE-2019-5824 [HIGH] CVE-2019-5824 chromium: chromium-browser: parameter passing error in media player leading to unauthorized access [epel-7]
CVE-2019-5824 chromium: chromium-browser: parameter passing error in media player leading to unauthorized access [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Bugzilla
CVE-2019-5824 chromium: chromium-browser: parameter passing error in media player leading to unauthorized access [fedora-all]
bugzilla·2019-05-06·CVSS 8.8
CVE-2019-5824 [HIGH] CVE-2019-5824 chromium: chromium-browser: parameter passing error in media player leading to unauthorized access [fedora-all]
CVE-2019-5824 chromium: chromium-browser: parameter passing error in media player leading to unauthorized access [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2016-5824 libical: Multiple use-after-free vulnerabilities
bugzilla·2016-09-12·CVSS 5.5
CVE-2016-5824 [MEDIUM] CVE-2016-5824 libical: Multiple use-after-free vulnerabilities
CVE-2016-5824 libical: Multiple use-after-free vulnerabilities
Multiple use after free vulnerabilities possibly having the same root cause was found in libical.
Upstream bug:
https://bugzilla.mozilla.org/show_bug.cgi?id=1275400
CVE assignment:
http://seclists.org/oss-sec/2016/q2/604
Discussion:
Created thunderbird tracking bugs for this issue:
Affects: fedora-all [bug 1375122]
---
Created libical tracking bugs for this issue:
Affects: fedora-all [bug 1375121]
Affects: epel-5 [bug 1375123]
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2019-03/
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2019:0269 https://access.redhat.com/errata/RHSA-2019:0269
---
This issue has been addressed in the fo
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00085.htmlhttps://chromereleases.googleblog.com/2019/04/stable-channel-update-for-desktop_30.htmlhttps://crbug.com/948564https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CPM7VPE27DUNJLXM4F5PAAEFFWOEND6X/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FKN4GPMBQ3SDXWB4HL45II5CZ7P2E4AI/https://seclists.org/bugtraq/2019/Aug/19https://www.debian.org/security/2019/dsa-4500http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00085.htmlhttps://chromereleases.googleblog.com/2019/04/stable-channel-update-for-desktop_30.htmlhttps://crbug.com/948564https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CPM7VPE27DUNJLXM4F5PAAEFFWOEND6X/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FKN4GPMBQ3SDXWB4HL45II5CZ7P2E4AI/https://seclists.org/bugtraq/2019/Aug/19https://www.debian.org/security/2019/dsa-4500
2019-06-27
Published