CVE-2019-13751: SQL Injection
An uninitialized use flaw was found in the SQLite component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1025465
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Other sources
Uninitialized data in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-13751.
What is the severity of CVE-2019-13751?
The severity of CVE-2019-13751 is medium.
Which software versions are affected by CVE-2019-13751?
Google Chrome versions prior to 79.0.3945.79 are affected by CVE-2019-13751.
How can a remote attacker exploit CVE-2019-13751?
A remote attacker can exploit CVE-2019-13751 by crafting an HTML page to obtain potentially sensitive information from process memory.
Where can I find more information about CVE-2019-13751?
You can find more information about CVE-2019-13751 at the following references: [Reference 1](https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html), [Reference 2](https://crbug.com/1025465), [Reference 3](https://access.redhat.com/errata/RHSA-2019:4238).