CVE-2019-11070
webkitgtk: HTTP proxy setting deanonymization information disclosure
Severity Score
5.3
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded.
WebKitGTK y WPE WebKit en las versiones anteriores a 2.24.1 no aplican correctamente la configuración del proxy HTTP al descargar vídeo en directo (HLS, DASH o Smooth Streaming), lo que provocó un error de desanonimización. Este problema se corrigió cambiando la forma en que se descargan las transmisiones en directo.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2019-04-10 CVE Reserved
- 2019-04-10 CVE Published
- 2024-08-04 CVE Updated
- 2024-10-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-19: Data Processing Errors
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/152485/WebKitGTK-WPE-WebKit-URI-Spoofing-Code-Execution.html | Third Party Advisory | |
http://www.openwall.com/lists/oss-security/2019/04/11/1 | Mailing List | |
https://bugs.webkit.org/show_bug.cgi?id=193718 | Issue Tracking | |
https://seclists.org/bugtraq/2019/Apr/21 | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://trac.webkit.org/changeset/243197/webkit | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Webkitgtk Search vendor "Webkitgtk" | Webkitgtk Search vendor "Webkitgtk" for product "Webkitgtk" | < 2.24.1 Search vendor "Webkitgtk" for product "Webkitgtk" and version " < 2.24.1" | - |
Affected
| ||||||
Wpewebkit Search vendor "Wpewebkit" | Wpe Webkit Search vendor "Wpewebkit" for product "Wpe Webkit" | < 2.24.1 Search vendor "Wpewebkit" for product "Wpe Webkit" and version " < 2.24.1" | - |
Affected
|