CVE-2018-11713

Priority
Description
WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup
network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or
without libsoup 2.62.0, unexpectedly failed to use system proxy settings
for WebSocket connections. As a result, users could be deanonymized by
crafted web sites via a WebSocket connection.
Notes
jdstrandwebkit receives limited support. For details, see
https://wiki.ubuntu.com/SecurityTeam/FAQ#webkit
webkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8
mdeslaurIt looks like this requires a new API introduced in libsoup
2.62.0 to be fixed. We are not going to backport the new API.
Marking releases older than bionic as ignored.
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 18.04 LTS (Bionic Beaver):DNE
Ubuntu 19.10 (Eoan Ermine):needs-triage
Ubuntu 20.04 (Focal Fossa):DNE
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE (trusty was needs-triage)
Ubuntu 16.04 LTS (Xenial Xerus):needs-triage
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 19.10 (Eoan Ermine):needs-triage
Ubuntu 20.04 (Focal Fossa):needs-triage
Patches:
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE (trusty was needs-triage)
Ubuntu 16.04 LTS (Xenial Xerus):needs-triage
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 19.10 (Eoan Ermine):DNE
Ubuntu 20.04 (Focal Fossa):DNE
Package
Upstream:released (2.62.0)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):ignored
Ubuntu 18.04 LTS (Bionic Beaver):not-affected (2.20.2-0ubuntu0.18.04.1)
Ubuntu 19.10 (Eoan Ermine):not-affected (2.20.3-1)
Ubuntu 20.04 (Focal Fossa):not-affected (2.20.3-1)
Patches:
Upstream:https://trac.webkit.org/changeset/228088/webkit
Upstream:https://gitlab.gnome.org/GNOME/libsoup/commit/d852881f1ab7d6107b2581d3a28d3529b85ea298
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE (trusty was needs-triage)
Ubuntu 16.04 LTS (Xenial Xerus):needs-triage
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 19.10 (Eoan Ermine):DNE
Ubuntu 20.04 (Focal Fossa):DNE
More Information

Updated: 2020-01-29 18:51:27 UTC (commit 40f18bf14da5fb50662e1f861ea594a462b207fe)