PT-2019-4959 · Apple+7 · Wpe Webkit+8

Michael Catanzaro

·

Published

2019-01-23

·

Updated

2020-10-20

·

CVE-2019-11070

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WebKitGTK and WPE WebKit versions prior to 2.24.1
Description The issue is related to the incorrect handling of data when loading video in real-time, which can allow a remote attacker to gain unauthorized access to protected information. This is due to the failure to properly apply configured HTTP proxy settings when downloading livestream video, resulting in deanonymization.
Recommendations For versions prior to 2.24.1, update to version 2.24.1 or later to resolve the issue. As a temporary workaround, consider restricting access to livestream video downloads until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2019:3553
ALT-PU-2019-1637
BDU:2020-01579
CESA-2019_3553
CESA-2020_4035
CVE-2019-11070
OPENSUSE-SU-2019:1374-1
OPENSUSE-SU-2019_1374-1
OPENSUSE-SU-2019_1391-1
RHSA-2019:3553
RHSA-2019_3553
RHSA-2020:4035
RHSA-2020_4035
RLSA-2019:3553
SUSE-SU-2019:1137-1
SUSE-SU-2019:1155-1
SUSE-SU-2019_1155-1
USN-3948-1

Affected Products

Alt Linux
Almalinux
Centos
Red Hat
Rocky Linux
Suse
Ubuntu
Wpe Webkit
Webkitgtk