CVE-2018-11713

Priority
Description
WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup
network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or
without libsoup 2.62.0, unexpectedly failed to use system proxy settings
for WebSocket connections. As a result, users could be deanonymized by
crafted web sites via a WebSocket connection.
Notes
jdstrandwebkit receives limited support. For details, see
https://wiki.ubuntu.com/SecurityTeam/FAQ#webkit
webkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8
mdeslaurIt looks like this requires a new API introduced in libsoup
2.62.0 to be fixed. We are not going to backport the new API.
Marking releases older than bionic as ignored.
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 18.04 LTS (Bionic Beaver):DNE
Ubuntu 20.04 LTS (Focal Fossa):DNE
Ubuntu 20.10 (Groovy Gorilla):DNE
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE (trusty was needs-triage)
Ubuntu 16.04 LTS (Xenial Xerus):needs-triage
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 20.04 LTS (Focal Fossa):needs-triage
Ubuntu 20.10 (Groovy Gorilla):needs-triage
Patches:
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE (trusty was needs-triage)
Ubuntu 16.04 LTS (Xenial Xerus):needs-triage
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 20.04 LTS (Focal Fossa):DNE
Ubuntu 20.10 (Groovy Gorilla):DNE
Package
Upstream:released (2.62.0)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):ignored
Ubuntu 18.04 LTS (Bionic Beaver):not-affected (2.20.2-0ubuntu0.18.04.1)
Ubuntu 20.04 LTS (Focal Fossa):not-affected (2.20.3-1)
Ubuntu 20.10 (Groovy Gorilla):not-affected (2.20.3-1)
Patches:
Upstream:https://trac.webkit.org/changeset/228088/webkit
Upstream:https://gitlab.gnome.org/GNOME/libsoup/commit/d852881f1ab7d6107b2581d3a28d3529b85ea298
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 ESM (Trusty Tahr):DNE (trusty was needs-triage)
Ubuntu 16.04 LTS (Xenial Xerus):needs-triage
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 20.04 LTS (Focal Fossa):DNE
Ubuntu 20.10 (Groovy Gorilla):DNE
More Information

Updated: 2020-07-28 18:48:49 UTC (commit 7b6828437fde0509248708fcdb5b0f7587b85bd1)