Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-11713

Опубликовано: 07 июн. 2018
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or without libsoup 2.62.0, unexpectedly failed to use system proxy settings for WebSocket connections. As a result, users could be deanonymized by crafted web sites via a WebSocket connection.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6webkitgtkWill not fix
Red Hat Enterprise Linux 7webkitgtk3Will not fix
Red Hat Enterprise Linux 8webkit2gtk3Not affected
Red Hat Enterprise Linux 7accountsserviceFixedRHSA-2018:314030.10.2018
Red Hat Enterprise Linux 7adwaita-icon-themeFixedRHSA-2018:314030.10.2018
Red Hat Enterprise Linux 7appstream-dataFixedRHSA-2018:314030.10.2018
Red Hat Enterprise Linux 7atkFixedRHSA-2018:314030.10.2018
Red Hat Enterprise Linux 7at-spi2-atkFixedRHSA-2018:314030.10.2018
Red Hat Enterprise Linux 7at-spi2-coreFixedRHSA-2018:314030.10.2018
Red Hat Enterprise Linux 7baobabFixedRHSA-2018:314030.10.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1588739webkitgtk: WebSockets don't use system proxy settings

EPSS

Процентиль: 67%
0.00551
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or without libsoup 2.62.0, unexpectedly failed to use system proxy settings for WebSocket connections. As a result, users could be deanonymized by crafted web sites via a WebSocket connection.

CVSS3: 6.5
nvd
больше 7 лет назад

WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or without libsoup 2.62.0, unexpectedly failed to use system proxy settings for WebSocket connections. As a result, users could be deanonymized by crafted web sites via a WebSocket connection.

CVSS3: 6.5
debian
больше 7 лет назад

WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the li ...

CVSS3: 6.5
github
больше 3 лет назад

WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or without libsoup 2.62.0, unexpectedly failed to use system proxy settings for WebSocket connections. As a result, users could be deanonymized by crafted web sites via a WebSocket connection.

suse-cvrf
больше 7 лет назад

Security update for webkit2gtk3

EPSS

Процентиль: 67%
0.00551
Низкий

5.3 Medium

CVSS3