VulnerabilityModified
CVE-2019-11070
WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization.
MEDIUM 5.3EPSS 3.29%
Does this matter?
Lower severity and a low EPSS score (3.29%). Track it; it rarely justifies an emergency change on its own.
Description
WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 3.29% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-19
- Affected
- webkitgtk/webkitgtk · wpewebkit/wpe webkit
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00031.html
- http://packetstormsecurity.com/files/152485/WebKitGTK-WPE-WebKit-URI-Spoofing-Code-Execution.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/04/11/1Third Party Advisory
- https://bugs.webkit.org/show_bug.cgi?id=193718Issue Tracking, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YO5ZBUWOOXMVZPBYLZRDZF6ZQGBYJERQ/
- https://seclists.org/bugtraq/2019/Apr/21Mailing List, Third Party Advisory, VDB Entry
- https://security.gentoo.org/glsa/201909-05
- https://trac.webkit.org/changeset/243197/webkitPatch, Vendor Advisory
- https://usn.ubuntu.com/3948-1/
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00031.html
- http://packetstormsecurity.com/files/152485/WebKitGTK-WPE-WebKit-URI-Spoofing-Code-Execution.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2019/04/11/1Third Party Advisory
- https://bugs.webkit.org/show_bug.cgi?id=193718Issue Tracking, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YO5ZBUWOOXMVZPBYLZRDZF6ZQGBYJERQ/
- https://seclists.org/bugtraq/2019/Apr/21Mailing List, Third Party Advisory, VDB Entry
- https://security.gentoo.org/glsa/201909-05
- https://trac.webkit.org/changeset/243197/webkitPatch, Vendor Advisory
- https://usn.ubuntu.com/3948-1/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.