Data Handling in WebKitGTK+ - CVE-2019-11070

 

Data Handling in WebKitGTK+ - CVE-2019-11070

Published: April 10, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU31117
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11070
CWE-ID: CWE-19
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded.


Affected software

WebKitGTK+
webkit2gtk (Alpine package)
webkit2gtk3
Opensuse
Fedora

How to mitigate CVE-2019-11070

Install update from vendor's website.

WebKitGTK+ - update to 2.24.1
webkit2gtk (Alpine package) - update to 2.24.2-r0
webkit2gtk3 - update to 2.24.1-1.fc30

External References

Related Security Bulletins