All errata/sisyphus/ALT-PU-2018-1447-1
ALT-PU-2018-1447-1

Package update libwebkitgtk4 in branch sisyphus

Version2.20.0-alt1
Published2018-03-18
Max severityMEDIUM
Severity:

Closed issues (1)

CVE-2018-11713
MEDIUM6.5

WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or without libsoup 2.62.0, unexpectedly failed to use system proxy settings for WebSocket connections. As a result, users could be deanonymized by crafted web sites via a WebSocket connection.

Published: 2018-06-04Modified: 2024-11-21
CVSS 2.0MEDIUM 4.3
CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:P/A:N
CVSS 3.xMEDIUM 6.5
CVSS:3.x/CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N