Vulnerability Description
WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Webkitgtk | Webkitgtk | < 2.24.1 |
| Wpewebkit | Wpe Webkit | < 2.24.1 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00031.html
- http://packetstormsecurity.com/files/152485/WebKitGTK-WPE-WebKit-URI-Spoofing-CoThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/04/11/1Third Party Advisory
- https://bugs.webkit.org/show_bug.cgi?id=193718Issue TrackingThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://seclists.org/bugtraq/2019/Apr/21Mailing ListThird Party AdvisoryVDB Entry
- https://security.gentoo.org/glsa/201909-05
- https://trac.webkit.org/changeset/243197/webkitPatchVendor Advisory
- https://usn.ubuntu.com/3948-1/
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00031.html
- http://packetstormsecurity.com/files/152485/WebKitGTK-WPE-WebKit-URI-Spoofing-CoThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/04/11/1Third Party Advisory
- https://bugs.webkit.org/show_bug.cgi?id=193718Issue TrackingThird Party Advisory
FAQ
What is CVE-2019-11070?
CVE-2019-11070 is a vulnerability with a CVSS score of 5.3 (MEDIUM). WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deano...
How severe is CVE-2019-11070?
CVE-2019-11070 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-11070?
Check the references section above for vendor advisories and patch information. Affected products include: Webkitgtk Webkitgtk, Wpewebkit Wpe Webkit.