PT-2019-4962 · Apple+7 · Webkitgtk+8

Dhiraj

·

Published

2018-09-11

·

Updated

2024-06-15

·

CVE-2019-6251

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WebKitGTK and WPE WebKit versions prior to 2.24.1
Description The issue is related to insufficient input validation in WebKitGTK and WPE WebKit, allowing an attacker to conduct spoofing attacks. This can cause malicious web content to be displayed as if it were from a trusted URI, potentially deceiving users. The attack can be initiated remotely and involves certain JavaScript redirections.
Recommendations For WebKitGTK and WPE WebKit versions prior to 2.24.1, update to version 2.24.1 or later to resolve the issue. As a temporary workaround, consider restricting JavaScript redirections in the browser settings until the update is applied.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2019:3553
ALT-PU-2019-1458
ALT-PU-2019-1637
BDU:2020-01582
CESA-2019_3553
CESA-2020_4035
CVE-2019-6251
OPENSUSE-SU-2019:1374-1
OPENSUSE-SU-2019_1374-1
OPENSUSE-SU-2019_1391-1
OPENSUSE-SU-2024:11506-1
RHSA-2019:3553
RHSA-2019_3553
RHSA-2020:4035
RHSA-2020_4035
RLSA-2019:3553
SUSE-SU-2019:1137-1
SUSE-SU-2019:1155-1
USN-3948-1

Affected Products

Alt Linux
Almalinux
Centos
Red Hat
Rocky Linux
Suse
Ubuntu
Wpe Webkit
Webkitgtk