CVE-2019-6251Improper Input Validation in Webkitgtk

Severity
8.1HIGHNVD
CNA4.3OSV4.3
EPSS
2.4%
top 14.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 14
Latest updateMay 13

Description

WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages4 packages

NVDwebkitgtk/webkitgtk< 2.24.1
NVDwpewebkit/wpe_webkit< 2.24.1
NVDgnome/epiphany3.31.4
NVDopensuse/leap15.0, 42.3+1

Also affects: Fedora 28, 29, 30, Ubuntu Linux 18.04, 18.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-w36c-w6x2-gj2r: WebKitGTK and WPE WebKit prior to version 22022-05-13
CVEList
CVE-2019-6251: WebKitGTK and WPE WebKit prior to version 22019-01-14
OSV
CVE-2019-6251: WebKitGTK and WPE WebKit prior to version 22019-01-14

📋Vendor Advisories

3
Ubuntu
WebKitGTK+ vulnerabilities2019-04-16
Debian
CVE-2019-6251: webkit2gtk - WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar s...2019
Red Hat
webkitgtk: processing maliciously crafted web content lead to URI spoofing2018-09-11

💬Community

6
Bugzilla
CVE-2019-6251 webkit2gtk3: webkitgtk: processing maliciously crafted web content lead to URI spoofing [fedora-all]2019-06-06
Bugzilla
CVE-2019-11070 CVE-2019-6251 mingw-webkitgtk3: various flaws [epel-7]2019-05-13
Bugzilla
CVE-2019-11070 CVE-2019-6251 mingw-webkitgtk: various flaws [epel-7]2019-05-13
Bugzilla
CVE-2019-11070 CVE-2019-6251 mingw-webkitgtk: various flaws [fedora-all]2019-05-13
Bugzilla
CVE-2019-6251 webkitgtk: processing maliciously crafted web content lead to URI spoofing2019-01-18
CVE-2019-6251 — Improper Input Validation in Webkitgtk | cvebase