CVE-2019-11070: Medium severity oracle webkitgtk4-jsc vulnerability
Last updated 24 July 2024
Other sources
WebKitGTK and WPE WebKit failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded.
Reference: https://webkitgtk.org/security/WSA-2019-0002.html https://wpewebkit.org/security/WSA-2019-0002.html
— Red Hat
WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-11070?
CVE-2019-11070 is a vulnerability in WebKitGTK and WPE WebKit prior to version 2.24.1 that failed to properly apply configured HTTP proxy settings when downloading livestream video, leading to deanonymization.
How severe is CVE-2019-11070?
CVE-2019-11070 has a severity score of 5.3, which is considered medium.
How can I fix CVE-2019-11070?
To fix CVE-2019-11070, update WebKitGTK and WPE WebKit to version 2.24.1 or later.
Where can I find more information about CVE-2019-11070?
More information about CVE-2019-11070 can be found on the MITRE CVE website (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11070), the WebKitGTK security advisory (https://webkitgtk.org/security/WSA-2019-0002.html), and the WebKit changeset (https://trac.webkit.org/changeset/243197/webkit).