CVE-2019-5829: Integer Overflow
Integer overflow in download manager in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this Chrome vulnerability?
The vulnerability ID for this Chrome vulnerability is CVE-2019-5829.
What is the severity of CVE-2019-5829?
The severity of CVE-2019-5829 is high with a score of 8.8.
Which software versions are affected by CVE-2019-5829?
Google Chrome versions prior to 75.0.3770.80, Opensuse Backports sle-15, openSUSE Leap 15.0/15.1/42.3, Debian Debian Linux 10.0, Fedoraproject Fedora 29/30, and chromium Debian package versions mentioned in the reference link are affected.
How can a remote attacker exploit CVE-2019-5829?
A remote attacker can exploit CVE-2019-5829 by using a crafted HTML page that triggers an integer overflow in the download manager, allowing them to potentially perform out of bounds memory access.
How can I fix CVE-2019-5829?
To fix CVE-2019-5829, update your Google Chrome browser to version 75.0.3770.80 or later, or update the chromium Debian package to the versions mentioned in the reference link for Debian Linux.