CVE-2019-11070
Summary
| CVE | CVE-2019-11070 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-10 21:29:00 UTC |
| Updated | 2023-11-07 03:02:00 UTC |
| Description | WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [security-announce] openSUSE-SU-2019:1374-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| USN-3948-1: WebKitGTK+ vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
|
| [SECURITY] Fedora 30 Update: webkit2gtk3-2.24.1-1.fc30 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [security-announce] openSUSE-SU-2019:1391-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| WebKitGTK+ / WPE WebKit URI Spoofing / Code Execution ≈ Packet Storm |
MISC |
packetstormsecurity.com |
Third Party Advisory |
| [SECURITY] Fedora 30 Update: webkit2gtk3-2.24.1-1.fc30 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| 193718 – (CVE-2019-11070) [GStreamer] HLS, DASH, and Smooth Streaming implementations ignore proxy settings |
MISC |
bugs.webkit.org |
Issue Tracking, Third Party Advisory |
| Changeset 243197 – WebKit |
MISC |
trac.webkit.org |
Patch, Vendor Advisory |
| Bugtraq: WebKitGTK and WPE WebKit Security Advisory WSA-2019-0002 |
BUGTRAQ |
seclists.org |
Mailing List, Third Party Advisory, VDB Entry |
| oss-security - WebKitGTK and WPE WebKit Security Advisory WSA-2019-0002 |
MLIST |
www.openwall.com |
Third Party Advisory |
| WebkitGTK+: Multiple vulnerabilities (GLSA 201909-05) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296078 Oracle Solaris 11.4 Support Repository Update (SRU) 16.4.0 Missing (CPUOCT2019)
- 377553 Alibaba Cloud Linux Security Update for webkitgtk4 (ALINUX2-SA-2020:0147)
- 501282 Alpine Linux Security Update for webkit2gtk
- 505503 Alpine Linux Security Update for webkit2gtk
- 710127 Gentoo Linux WebkitGTK+ Multiple vulnerabilities (GLSA 201909-05)
- 940366 AlmaLinux Security Update for GNOME (ALSA-2019:3553)
- 960235 Rocky Linux Security Update for GNOME (RLSA-2019:3553)