CVE-2015-8079: Infoleak
qt5-qtwebkit before 5.4 records private browsing URLs to its favicon database, WebpageIcons.db.
Other sources
QtWebKit upstream are reviewing a patch that prevents it recording visited URLs to its favicon database (WebpageIcons.db) while using private browsing mode:
- https://codereview.qt-project.org/#/c/108936/
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8079?
CVE-2015-8079 has been identified as a vulnerability that could lead to privacy issues in applications using affected versions of QtWebKit.
How do I fix CVE-2015-8079?
To fix CVE-2015-8079, update QtWebKit to version 5.4 or later where the issue has been resolved.
Which versions of QtWebKit are affected by CVE-2015-8079?
CVE-2015-8079 affects all versions of QtWebKit prior to 5.4.
What kind of data is at risk due to CVE-2015-8079?
CVE-2015-8079 risks the leaking of URLs visited during private browsing sessions to the favicon database.
Is there a workaround for CVE-2015-8079 if I cannot update?
There is no documented workaround for CVE-2015-8079 other than upgrading to the fixed version.