CVE-2015-3750

Publication date 16 August 2015

Last updated 24 July 2024


Ubuntu priority

WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not enforce the HTTP Strict Transport Security (HSTS) protection mechanism for Content Security Policy (CSP) report requests, which allows man-in-the-middle attackers to obtain sensitive information by sniffing the network or spoof a report by modifying the client-server data stream.

Read the notes from the security team

Status

Package Ubuntu Release Status
qtwebkit-opensource-src 16.10 yakkety Ignored end of life
16.04 LTS xenial Ignored no update available
15.10 wily Ignored end of life
15.04 vivid Ignored end of life
14.04 LTS trusty Not in release
12.04 LTS precise Not in release
qtwebkit-source 16.10 yakkety Ignored end of life
16.04 LTS xenial Ignored no update available
15.10 wily Ignored end of life
15.04 vivid Ignored end of life
14.04 LTS trusty Not in release
12.04 LTS precise Ignored end of life
webkit 16.10 yakkety Not in release
16.04 LTS xenial Not in release
15.10 wily Not in release
15.04 vivid Not in release
14.04 LTS trusty Not in release
12.04 LTS precise Ignored end of life
webkitgtk 16.10 yakkety Ignored end of life
16.04 LTS xenial Ignored no update available
15.10 wily Ignored end of life
15.04 vivid Ignored end of life
14.04 LTS trusty Not in release
12.04 LTS precise Not in release

Notes


jdstrand

webkit receives limited support. For details, see https://wiki.ubuntu.com/SecurityTeam/FAQ#webkit webkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8