Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-6251

Опубликовано: 14 янв. 2019
Источник: debian

Описание

WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
webkit2gtkfixed2.24.1-1package
webkit2gtkignoredstretchpackage
webkit2gtkignoredjessiepackage

Примечания

  • https://gitlab.gnome.org/GNOME/epiphany/issues/532

  • https://bugs.webkit.org/show_bug.cgi?id=194131

  • https://bugs.webkit.org/show_bug.cgi?id=194208

  • https://webkitgtk.org/security/WSA-2019-0002.html

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 6 лет назад

WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.

CVSS3: 4.3
redhat
почти 7 лет назад

WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.

CVSS3: 8.1
nvd
больше 6 лет назад

WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.

CVSS3: 8.1
github
около 3 лет назад

WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.

CVSS3: 8.1
fstec
больше 6 лет назад

Уязвимость модулей отображения веб-страниц WebKitGTK и WPE WebKit, связанная с недостаточной проверкой входных данных, позволяющая нарушителю проводить спуфинг-атаки