CVE-2019-5836: Buffer Overflow
Heap buffer overflow in ANGLE in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-5836?
CVE-2019-5836 is a vulnerability that allows a remote attacker to potentially exploit heap corruption in ANGLE in Google Chrome prior to version 75.0.3770.80 via a crafted HTML page.
How severe is CVE-2019-5836?
CVE-2019-5836 has a severity score of 8.8 (high severity).
What software versions are affected by CVE-2019-5836?
Google Chrome versions prior to 75.0.3770.80, Opensuse Backports sle-15, openSUSE Leap 15.0, openSUSE Leap 15.1, openSUSE Leap 42.3, Debian Debian Linux 10.0, Fedoraproject Fedora 29, Fedoraproject Fedora 30, and chromium versions listed in the reference are affected by CVE-2019-5836.
How can I fix CVE-2019-5836?
Update Google Chrome to version 75.0.3770.80 or later, or follow the remedy instructions provided in the reference for Opensuse Backports, openSUSE Leap, Debian Debian Linux, and Fedoraproject Fedora.
Where can I find more information about CVE-2019-5836?
You can find more information about CVE-2019-5836 at the references provided: http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00085.html, https://chromereleases.googleblog.com/2019/06/stable-channel-update-for-desktop.html, https://crbug.com/947342