Vulnerability Name:

CVE-2019-13720 (CCN-170818)

Assigned:2019-10-31
Published:2019-10-31
Updated:2022-10-06
Summary:Use after free in WebAudio in Google Chrome prior to 78.0.3904.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.9 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
8.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.9 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-416
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2019-13720

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2019:2664

Source: MISC
Type: Exploit, Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/167066/Google-Chrome-78.0.3904.70-Remote-Code-Execution.html

Source: CCN
Type: Google Chrome Releases Web site
Stable Channel Update for Desktop

Source: MISC
Type: Vendor Advisory
https://chromereleases.googleblog.com/2019/10/stable-channel-update-for-desktop_31.html

Source: MISC
Type: Permissions Required
https://crbug.com/1019226

Source: XF
Type: UNKNOWN
google-chrome-cve201913720-code-exec(170818)

Source: CCN
Type: Packet Storm Security [05-11-2022]
Google Chrome 78.0.3904.70 Remote Code Execution

Source: CCN
Type: SECURELIST Web site
Chrome 0-day exploit CVE-2019-13720 used in Operation WizardOpium

Source: GENTOO
Type: Third Party Advisory
GLSA-202004-04

Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database [05-11-2022]

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2019-13720

Vulnerable Configuration:Configuration 1:
  • cpe:/a:google:chrome:*:*:*:*:*:*:*:* (Version < 78.0.3904.87)

  • Configuration 2:
  • cpe:/o:opensuse:leap:15.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201913720
    V
    CVE-2019-13720
    2022-06-30
    oval:org.opensuse.security:def:93483
    P
    (Moderate)
    2022-03-04
    oval:org.opensuse.security:def:112066
    P
    chromedriver-93.0.4577.82-1.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:105615
    P
    chromedriver-93.0.4577.82-1.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:63230
    P
    postgresql-contrib-10-6.8 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:74307
    P
    Security update for ffmpeg (Important)
    2021-09-02
    oval:org.opensuse.security:def:63318
    P
    apache2-mod_nss-1.0.17-3.3.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63368
    P
    qemu-5.2.0-9.18 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63028
    P
    openldap2-devel-32bit-2.4.46-9.51.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62749
    P
    gdm-3.34.1-8.15.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:74357
    P
    Security update for gupnp (Important)
    2021-06-24
    oval:org.opensuse.security:def:63544
    P
    libavcodec-devel-3.4.2-2.35 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:62499
    P
    wireshark-devel-2.4.6-1.31 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63594
    P
    libstaroffice-0_0-0-0.0.6-5.17 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63180
    P
    salt-api-2018.3.0-3.9 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62498
    P
    wavpack-5.1.0-2.17 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62978
    P
    perl-YAML-LibYAML-0.59-1.16 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62549
    P
    libexempi-devel-2.4.5-1.11 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62699
    P
    libsrt1-1.3.4-1.45 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62548
    P
    libcdio++0-0.94-6.6.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62522
    P
    gnome-online-accounts-devel-3.26.2-3.34 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62572
    P
    libopus-devel-1.2.1-1.29 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:25084
    P
    Security update for clamav (Important)
    2020-12-01
    oval:org.opensuse.security:def:26420
    P
    Security update for phpMyAdmin (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64305
    P
    libXinerama-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25636
    P
    Security update for libproxy (Important)
    2020-12-01
    oval:org.opensuse.security:def:25020
    P
    Security update for ibus (Important)
    2020-12-01
    oval:org.opensuse.security:def:25782
    P
    Security update for evolution-data-server (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64263
    P
    glibc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25583
    P
    Security update for python36 (Important)
    2020-12-01
    oval:org.opensuse.security:def:74433
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:25738
    P
    Security update for libxslt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64111
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:25433
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:25724
    P
    Security update for postgresql10 (Low)
    2020-12-01
    oval:org.opensuse.security:def:64005
    P
    Security update for python-aws-sam-translator, python-boto3, python-botocore, python-cfn-lint, python-jsonschema, python-nose2, python-parameterized, python-pathlib2, python-pytest-cov, python-requests, python-s3transfer (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25349
    P
    Security update for bluez (Important)
    2020-12-01
    oval:org.opensuse.security:def:74483
    P
    Security update for opera (Important)
    2020-12-01
    oval:org.opensuse.security:def:64367
    P
    libpcsclite1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64161
    P
    Security update for freetype2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:63871
    P
    Security update for openssl-1_0_0 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25292
    P
    Security update for libX11 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25009
    P
    Security update for libsolv, libzypp, zypper (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64255
    P
    g3utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64055
    P
    Security update for python-ipaddress (Important)
    2020-12-01
    oval:org.opensuse.security:def:25211
    P
    Security update for mariadb-100 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26455
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:64417
    P
    minicom on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64213
    P
    augeas on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63921
    P
    Security update for openldap2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:100196
    P
    (Moderate)
    2020-05-18
    oval:org.opensuse.security:def:110107
    P
    Security update for opera (Important)
    2019-12-10
    oval:com.ubuntu.disco:def:2019137200000000
    V
    CVE-2019-13720 on Ubuntu 19.04 (disco) - medium.
    2019-11-25
    oval:com.ubuntu.bionic:def:2019137200000000
    V
    CVE-2019-13720 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-11-25
    oval:com.ubuntu.xenial:def:2019137200000000
    V
    CVE-2019-13720 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-11-25
    oval:org.opensuse.security:def:110057
    P
    Security update for chromium (Important)
    2019-11-02
    BACK
    google chrome *
    opensuse leap 15.1