Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-11712

Опубликовано: 04 июн. 2018
Источник: debian
EPSS Низкий

Описание

WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ versions 2.20.0 and 2.20.1, failed to perform TLS certificate verification for WebSocket connections.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
webkit2gtkfixed2.20.2-1package

Примечания

  • https://bugs.webkit.org/show_bug.cgi?id=184804

  • https://trac.webkit.org/changeset/230886/webkit

  • Not covered by security support

  • https://webkitgtk.org/security/WSA-2018-0005.html

EPSS

Процентиль: 46%
0.00228
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 7 лет назад

WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ versions 2.20.0 and 2.20.1, failed to perform TLS certificate verification for WebSocket connections.

CVSS3: 7.5
redhat
около 7 лет назад

WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ versions 2.20.0 and 2.20.1, failed to perform TLS certificate verification for WebSocket connections.

CVSS3: 7.5
nvd
около 7 лет назад

WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ versions 2.20.0 and 2.20.1, failed to perform TLS certificate verification for WebSocket connections.

CVSS3: 7.5
github
больше 3 лет назад

WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ versions 2.20.0 and 2.20.1, failed to perform TLS certificate verification for WebSocket connections.

suse-cvrf
почти 7 лет назад

Security update for webkit2gtk3

EPSS

Процентиль: 46%
0.00228
Низкий