Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.2.2019.2196
Kategorie:Huawei EulerOS Local Security Checks
Titel:Huawei EulerOS: Security Advisory for webkitgtk3 (EulerOS-SA-2019-2196)
Zusammenfassung:The remote host is missing an update for the Huawei EulerOS 'webkitgtk3' package(s) announced via the EulerOS-SA-2019-2196 advisory.
Beschreibung:Summary:
The remote host is missing an update for the Huawei EulerOS 'webkitgtk3' package(s) announced via the EulerOS-SA-2019-2196 advisory.

Vulnerability Insight:
WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirections. An attacker could cause malicious web content to be displayed as if for a trusted URI. This is similar to the CVE-2018-8383 issue in Microsoft Edge.(CVE-2019-6251)

Affected Software/OS:
'webkitgtk3' package(s) on Huawei EulerOS V2.0SP5.

Solution:
Please install the updated package(s).

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2019-6251
Bugtraq: 20190411 WebKitGTK and WPE WebKit Security Advisory WSA-2019-0002 (Google Search)
https://seclists.org/bugtraq/2019/Apr/21
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LACVFU4MYYRPJ3IEA4UCN5KUEAGCCJ72/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HSCDI3635E37GL4BNJDRDT2KEUBDLGSO/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UO3DIA54X7FOUWFZW5YXC2MZ6KNHG6SW/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TNPI3R6QWDJBA5KNGA6QSMKYLY5RRHBZ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YO5ZBUWOOXMVZPBYLZRDZF6ZQGBYJERQ/
https://security.gentoo.org/glsa/201909-05
http://packetstormsecurity.com/files/152485/WebKitGTK-WPE-WebKit-URI-Spoofing-Code-Execution.html
https://bugs.webkit.org/show_bug.cgi?id=194208
https://gitlab.gnome.org/GNOME/epiphany/issues/532
https://trac.webkit.org/changeset/243434
http://www.openwall.com/lists/oss-security/2019/04/11/1
SuSE Security Announcement: openSUSE-SU-2019:1374 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00025.html
SuSE Security Announcement: openSUSE-SU-2019:1391 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00031.html
https://usn.ubuntu.com/3948-1/
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.