vulnerability
Oracle Linux: CVE-2019-11070: ELSA-2020-4035: webkitgtk4 security, bug fix, and enhancement update (MODERATE) (Multiple Advisories)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
6 | (AV:N/AC:L/Au:N/C:P/I:P/A:N) | Apr 10, 2019 | Oct 7, 2020 | Nov 30, 2024 |
Severity
6
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:N)
Published
Apr 10, 2019
Added
Oct 7, 2020
Modified
Nov 30, 2024
Description
WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded.
Solution(s)
oracle-linux-upgrade-webkitgtk4oracle-linux-upgrade-webkitgtk4-develoracle-linux-upgrade-webkitgtk4-docoracle-linux-upgrade-webkitgtk4-jscoracle-linux-upgrade-webkitgtk4-jsc-devel

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.