webkitgtk: processing maliciously crafted web content lead to URI spoofing
Published Jan 14, 2019
8.1
HIGHCVSS 3.0
EPSS 4.26%
Description
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.
Affected products
No data.
Configuration 2
- < 2.24.1
- < 2.24.1
Configuration 3
- 28
- 29
- 30
Configuration 4
- 18.04
- 18.10
No data.
Red Hat Enterprise Linux 7
webkitgtk4-0:2.28.2-2.el7
Fixed · RHSA-2020:4035
Red Hat Enterprise Linux 8
SDL-0:1.2.15-35.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
SDL-0:1.2.15-35.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
accountsservice-0:0.6.50-7.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
accountsservice-0:0.6.50-7.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
appstream-data-0:8-20190805.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
appstream-data-0:8-20190805.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
baobab-0:3.28.0-2.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
baobab-0:3.28.0-2.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
chrome-gnome-shell-0:10.1-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
chrome-gnome-shell-0:10.1-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
evince-0:3.28.4-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
evince-0:3.28.4-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
file-roller-0:3.28.1-2.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
file-roller-0:3.28.1-2.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gdk-pixbuf2-0:2.36.12-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gdk-pixbuf2-0:2.36.12-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gdm-1:3.28.3-22.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gdm-1:3.28.3-22.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gjs-0:1.56.2-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gjs-0:1.56.2-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-control-center-0:3.28.2-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-control-center-0:3.28.2-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-desktop3-0:3.32.2-1.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-desktop3-0:3.32.2-1.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-remote-desktop-0:0.1.6-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-remote-desktop-0:0.1.6-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-settings-daemon-0:3.32.0-4.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-settings-daemon-0:3.32.0-4.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-shell-0:3.32.2-9.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-shell-0:3.32.2-9.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-shell-extensions-0:3.32.1-10.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-shell-extensions-0:3.32.1-10.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-software-0:3.30.6-2.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-software-0:3.30.6-2.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-tweaks-0:3.28.1-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gnome-tweaks-0:3.28.1-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gsettings-desktop-schemas-0:3.32.0-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gsettings-desktop-schemas-0:3.32.0-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gtk3-0:3.22.30-4.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gtk3-0:3.22.30-4.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gvfs-0:1.36.2-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
gvfs-0:1.36.2-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
mozjs60-0:60.9.0-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
mozjs60-0:60.9.0-3.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
mutter-0:3.32.2-10.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
mutter-0:3.32.2-10.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
nautilus-0:3.28.1-10.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
nautilus-0:3.28.1-10.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
pango-0:1.42.4-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
pango-0:1.42.4-6.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
pidgin-0:2.13.0-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
pidgin-0:2.13.0-5.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
plymouth-0:0.9.3-15.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
plymouth-0:0.9.3-15.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
wayland-protocols-0:1.17-1.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
wayland-protocols-0:1.17-1.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
webkit2gtk3-0:2.24.3-1.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 8
webkit2gtk3-0:2.24.3-1.el8
Fixed · RHSA-2019:3553
Red Hat Enterprise Linux 6
webkitgtk
Out of support scope
Red Hat Enterprise Linux 7
webkitgtk3
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | webkitgtk4-0:2.28.2-2.el7 | Fixed | RHSA-2020:4035 |
| Red Hat Enterprise Linux 8 | SDL-0:1.2.15-35.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | SDL-0:1.2.15-35.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | accountsservice-0:0.6.50-7.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | accountsservice-0:0.6.50-7.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | appstream-data-0:8-20190805.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | appstream-data-0:8-20190805.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | baobab-0:3.28.0-2.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | baobab-0:3.28.0-2.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | chrome-gnome-shell-0:10.1-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | chrome-gnome-shell-0:10.1-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | evince-0:3.28.4-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | evince-0:3.28.4-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | file-roller-0:3.28.1-2.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | file-roller-0:3.28.1-2.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gdk-pixbuf2-0:2.36.12-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gdk-pixbuf2-0:2.36.12-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gdm-1:3.28.3-22.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gdm-1:3.28.3-22.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gjs-0:1.56.2-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gjs-0:1.56.2-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-control-center-0:3.28.2-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-control-center-0:3.28.2-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-desktop3-0:3.32.2-1.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-desktop3-0:3.32.2-1.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-remote-desktop-0:0.1.6-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-remote-desktop-0:0.1.6-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-settings-daemon-0:3.32.0-4.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-settings-daemon-0:3.32.0-4.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-shell-0:3.32.2-9.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-shell-0:3.32.2-9.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-shell-extensions-0:3.32.1-10.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-shell-extensions-0:3.32.1-10.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-software-0:3.30.6-2.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-software-0:3.30.6-2.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-tweaks-0:3.28.1-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gnome-tweaks-0:3.28.1-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gsettings-desktop-schemas-0:3.32.0-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gsettings-desktop-schemas-0:3.32.0-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gtk3-0:3.22.30-4.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gtk3-0:3.22.30-4.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gvfs-0:1.36.2-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | gvfs-0:1.36.2-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | mozjs60-0:60.9.0-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | mozjs60-0:60.9.0-3.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | mutter-0:3.32.2-10.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | mutter-0:3.32.2-10.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | nautilus-0:3.28.1-10.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | nautilus-0:3.28.1-10.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | pango-0:1.42.4-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | pango-0:1.42.4-6.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | pidgin-0:2.13.0-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | pidgin-0:2.13.0-5.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | plymouth-0:0.9.3-15.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | plymouth-0:0.9.3-15.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | wayland-protocols-0:1.17-1.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | wayland-protocols-0:1.17-1.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | webkit2gtk3-0:2.24.3-1.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 8 | webkit2gtk3-0:2.24.3-1.el8 | Fixed | RHSA-2019:3553 |
| Red Hat Enterprise Linux 6 | webkitgtk | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | webkitgtk3 | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (20)
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00025.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00031.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://packetstormsecurity.com/files/152485/WebKitGTK-WPE-WebKit-URI-Spoofing-Code-Execution.html x_refsource_MISCThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2019/04/11/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-6251 Vendor Advisory
- https://bugs.webkit.org/show_bug.cgi?id=194208 x_refsource_MISCIssue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1667409 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-15818 Advisory
- https://gitlab.gnome.org/GNOME/epiphany/issues/532 x_refsource_MISCExploitPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HSCDI3635E37GL4BNJDRDT2KEUBDLGSO/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LACVFU4MYYRPJ3IEA4UCN5KUEAGCCJ72/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TNPI3R6QWDJBA5KNGA6QSMKYLY5RRHBZ/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UO3DIA54X7FOUWFZW5YXC2MZ6KNHG6SW/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YO5ZBUWOOXMVZPBYLZRDZF6ZQGBYJERQ/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2019-6251
- https://seclists.org/bugtraq/2019/Apr/21 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/201909-05 vendor-advisoryx_refsource_GENTOO
- https://trac.webkit.org/changeset/243434 x_refsource_MISCPatchVendor Advisory
- https://usn.ubuntu.com/3948-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-6251
Change history (0)
No recorded changes yet.