WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded.
Weaknesses in this category are typically found in functionality that processes data. Data processing is the manipulation of input to retrieve or save information.
Link | Tags |
---|---|
https://bugs.webkit.org/show_bug.cgi?id=193718 | issue tracking third party advisory |
https://trac.webkit.org/changeset/243197/webkit | patch vendor advisory |
https://seclists.org/bugtraq/2019/Apr/21 | mailing list vdb entry third party advisory |
http://www.openwall.com/lists/oss-security/2019/04/11/1 | third party advisory mailing list |
http://packetstormsecurity.com/files/152485/WebKitGTK-WPE-WebKit-URI-Spoofing-Code-Execution.html | third party advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YO5ZBUWOOXMVZPBYLZRDZF6ZQGBYJERQ/ | vendor advisory |
https://usn.ubuntu.com/3948-1/ | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00025.html | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00031.html | vendor advisory |
https://security.gentoo.org/glsa/201909-05 | vendor advisory |