First published: Mon Jun 04 2018(Updated: )
WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or without libsoup 2.62.0, unexpectedly failed to use system proxy settings for WebSocket connections. As a result, users could be deanonymized by crafted web sites via a WebSocket connection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webkitgtk Webkitgtk\+ | <2.20.0 | |
GNOME libsoup | <2.62.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11713 is a vulnerability in the libsoup network backend of WebKit, which could allow users to be deanonymized by crafting a malicious website.
The severity of CVE-2018-11713 is medium with a CVSS score of 6.5.
CVE-2018-11713 affects WebKitGTK+ versions prior to 2.20.0.
CVE-2018-11713 affects GNOME libsoup versions prior to 2.62.0.
The vulnerability can be fixed by updating WebKitGTK+ to version 2.20.0 or above, or by updating GNOME libsoup to version 2.62.0 or above.