First published: Wed Apr 10 2019(Updated: )
WebKitGTK and WPE WebKit failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded. Reference: <a href="https://webkitgtk.org/security/WSA-2019-0002.html">https://webkitgtk.org/security/WSA-2019-0002.html</a> <a href="https://wpewebkit.org/security/WSA-2019-0002.html">https://wpewebkit.org/security/WSA-2019-0002.html</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WebKitGTK WebKitGTK | <2.24.1 | |
Wpewebkit Wpe Webkit | <2.24.1 | |
redhat/webkitgtk | <2.24.1 | 2.24.1 |
ubuntu/webkit2gtk | <2.24.1-0ubuntu0.18.04.1 | 2.24.1-0ubuntu0.18.04.1 |
ubuntu/webkit2gtk | <2.24.1-0ubuntu0.18.10.2 | 2.24.1-0ubuntu0.18.10.2 |
ubuntu/webkit2gtk | <2.24.1 | 2.24.1 |
debian/webkit2gtk | 2.36.4-1~deb10u1 2.38.6-0+deb10u1 2.42.2-1~deb11u1 2.42.5-1~deb11u1 2.42.2-1~deb12u1 2.42.5-1~deb12u1 2.42.5-1 2.44.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11070 is a vulnerability in WebKitGTK and WPE WebKit prior to version 2.24.1 that failed to properly apply configured HTTP proxy settings when downloading livestream video, leading to deanonymization.
CVE-2019-11070 has a severity score of 5.3, which is considered medium.
To fix CVE-2019-11070, update WebKitGTK and WPE WebKit to version 2.24.1 or later.
More information about CVE-2019-11070 can be found on the MITRE CVE website (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11070), the WebKitGTK security advisory (https://webkitgtk.org/security/WSA-2019-0002.html), and the WebKit changeset (https://trac.webkit.org/changeset/243197/webkit).