CVE-2019-13753: SQL Injection
An out of bounds read flaw was found in the SQLite component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1025471
External References:
https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html
Other sources
Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-13753.
What is the severity of CVE-2019-13753?
The severity of CVE-2019-13753 is medium.
How can a remote attacker exploit CVE-2019-13753?
A remote attacker can exploit CVE-2019-13753 by using a crafted HTML page to obtain potentially sensitive information from process memory.
Is there a fix available for CVE-2019-13753?
Yes, a fix is available for CVE-2019-13753. Update to Google Chrome version 79.0.3945.79 or later.
Where can I find more information about CVE-2019-13753?
You can find more information about CVE-2019-13753 in the references provided: [Reference 1](https://chromereleases.googleblog.com/2019/12/stable-channel-update-for-desktop.html), [Reference 2](https://crbug.com/1025471), [Reference 3](https://access.redhat.com/errata/RHSA-2019:4238).