openSUSE-SU-2019:1374Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00025.html CVE-2019-11070
MEDIUM
Record summary
CVE-2019-11070 has a selected CVSS score of 5.3 (medium).
Description
WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded.
Description source: CVE List
References
12openSUSE-SU-2019:1391Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00031.html packetstormsecurity.com
http://packetstormsecurity.com/files/152485/WebKitGTK-WPE-WebKit-URI-Spoofing-Code-Execution.html [oss-security] 20190410 WebKitGTK and WPE WebKit Security Advisory WSA-2019-0002mailing list
http://www.openwall.com/lists/oss-security/2019/04/11/1 bugs.webkit.org
https://bugs.webkit.org/show_bug.cgi?id=193718 FEDORA-2019-d9a15be3baVendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YO5ZBUWOOXMVZPBYLZRDZF6ZQGBYJERQ lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YO5ZBUWOOXMVZPBYLZRDZF6ZQGBYJERQ nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-11070 20190411 WebKitGTK and WPE WebKit Security Advisory WSA-2019-0002mailing list
https://seclists.org/bugtraq/2019/Apr/21 GLSA-201909-05Vendor advisory
https://security.gentoo.org/glsa/201909-05 trac.webkit.org
https://trac.webkit.org/changeset/243197/webkit USN-3948-1Vendor advisory
https://usn.ubuntu.com/3948-1