PT-2019-4962 · Apple+7 · Webkitgtk+8

Dhiraj

·

Publicado

2018-09-11

·

Atualizado

2024-06-15

·

CVE-2019-6251

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WebKitGTK and WPE WebKit versions prior to 2.24.1
Description The issue is related to insufficient input validation in WebKitGTK and WPE WebKit, allowing an attacker to conduct spoofing attacks. This can cause malicious web content to be displayed as if it were from a trusted URI, potentially deceiving users. The attack can be initiated remotely and involves certain JavaScript redirections.
Recommendations For WebKitGTK and WPE WebKit versions prior to 2.24.1, update to version 2.24.1 or later to resolve the issue. As a temporary workaround, consider restricting JavaScript redirections in the browser settings until the update is applied.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2019:3553
ALT-PU-2019-1458
ALT-PU-2019-1637
BDU:2020-01582
CESA-2019_3553
CESA-2020_4035
CVE-2019-6251
OPENSUSE-SU-2019:1374-1
OPENSUSE-SU-2019_1374-1
OPENSUSE-SU-2019_1391-1
OPENSUSE-SU-2024:11506-1
RHSA-2019:3553
RHSA-2019_3553
RHSA-2020:4035
RHSA-2020_4035
RLSA-2019:3553
SUSE-SU-2019:1137-1
SUSE-SU-2019:1155-1
USN-3948-1

Produtos afetados

Alt Linux
Almalinux
Centos
Red Hat
Rocky Linux
Suse
Ubuntu
Wpe Webkit
Webkitgtk