PT-2019-4959 · Apple+7 · Wpe Webkit+8

Michael Catanzaro

·

Publicado

2019-01-23

·

Atualizado

2020-10-20

·

CVE-2019-11070

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WebKitGTK and WPE WebKit versions prior to 2.24.1
Description The issue is related to the incorrect handling of data when loading video in real-time, which can allow a remote attacker to gain unauthorized access to protected information. This is due to the failure to properly apply configured HTTP proxy settings when downloading livestream video, resulting in deanonymization.
Recommendations For versions prior to 2.24.1, update to version 2.24.1 or later to resolve the issue. As a temporary workaround, consider restricting access to livestream video downloads until the update is applied.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2019:3553
ALT-PU-2019-1637
BDU:2020-01579
CESA-2019_3553
CESA-2020_4035
CVE-2019-11070
OPENSUSE-SU-2019:1374-1
OPENSUSE-SU-2019_1374-1
OPENSUSE-SU-2019_1391-1
RHSA-2019:3553
RHSA-2019_3553
RHSA-2020:4035
RHSA-2020_4035
RLSA-2019:3553
SUSE-SU-2019:1137-1
SUSE-SU-2019:1155-1
SUSE-SU-2019_1155-1
USN-3948-1

Produtos afetados

Alt Linux
Almalinux
Centos
Red Hat
Rocky Linux
Suse
Ubuntu
Wpe Webkit
Webkitgtk