ZeroHour

CVE-2019-11070

CVSS 3.0
5.3 medium
EPSS
3%p88
Published
()
Modified
Description

WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded.

Vendors
webkitgtkwpewebkit
Products
webkitgtk, wpe webkit
Weakness
CWE-19
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.