CVE-2019-6251
Last modified
CVE-2019-6251 is a vulnerability of currently unknown severity. WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. EPSS estimates a 4.13% chance of exploitation in the next 30 days.
Description
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Epiphany | <= 3.31.4 |
| Webkitgtk | Webkitgtk | < 2.24.1 |
| Wpewebkit | Wpe Webkit | < 2.24.1 |
| Fedoraproject | Fedora | 28 |
| Fedoraproject | Fedora | 29 |
| Fedoraproject | Fedora | 30 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 18.10 |
| Opensuse | Leap | 15.0 |
| Opensuse | Leap | 42.3 |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00025.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00031.htmlThird Party Advisory
- http://packetstormsecurity.com/files/152485/WebKitGTK-WPE-WebKit-URI-Spoofing-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2019/04/11/1Mailing List, Third Party Advisory
- https://bugs.webkit.org/show_bug.cgi?id=194208Issue Tracking, Vendor Advisory
- https://gitlab.gnome.org/GNOME/epiphany/issues/532Exploit, Patch, Third Party Advisory
- https://seclists.org/bugtraq/2019/Apr/21Mailing List, Third Party Advisory
- https://trac.webkit.org/changeset/243434Patch, Vendor Advisory
- https://usn.ubuntu.com/3948-1/Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00025.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00031.htmlThird Party Advisory
- http://packetstormsecurity.com/files/152485/WebKitGTK-WPE-WebKit-URI-Spoofing-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2019/04/11/1Mailing List, Third Party Advisory
- https://bugs.webkit.org/show_bug.cgi?id=194208Issue Tracking, Vendor Advisory
- https://gitlab.gnome.org/GNOME/epiphany/issues/532Exploit, Patch, Third Party Advisory
- https://seclists.org/bugtraq/2019/Apr/21Mailing List, Third Party Advisory
- https://trac.webkit.org/changeset/243434Patch, Vendor Advisory
- https://usn.ubuntu.com/3948-1/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-6251?
How severe is CVE-2019-6251?
How do I fix CVE-2019-6251?
Are you affected by CVE-2019-6251?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
