CVE-2018-11713
04.06.2018, 14:29
WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or without libsoup 2.62.0, unexpectedly failed to use system proxy settings for WebSocket connections. As a result, users could be deanonymized by crafted web sites via a WebSocket connection.Enginsight
| Vendor | Product | Version |
|---|---|---|
| webkitgtk | webkitgtk\+ | 𝑥 < 2.20.0 |
| gnome | libsoup | 𝑥 < 2.62.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| qtwebkit |
| ||||||||||||||||||||||||||||||||
| qtwebkit-opensource-src |
| ||||||||||||||||||||||||||||||||
| qtwebkit-source |
| ||||||||||||||||||||||||||||||||
| webkit2gtk |
| ||||||||||||||||||||||||||||||||
| webkitgtk |
|