CVE-2018-6608

In the WebRTC component in Opera 51.0.2830.55, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), the browser can disclose a private IP address in a STUN request.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opera:opera_browser:51.0.2830.55:*:*:*:*:*:*:*

History

21 Nov 2024, 04:10

Type Values Removed Values Added
References () https://docs.google.com/spreadsheets/d/1Nm7mxfFvmdn-3Az-BtE5O0BIdbJiIAWUnkoAF_v_0ug/edit?usp=sharing - Third Party Advisory () https://docs.google.com/spreadsheets/d/1Nm7mxfFvmdn-3Az-BtE5O0BIdbJiIAWUnkoAF_v_0ug/edit?usp=sharing - Third Party Advisory
References () https://github.com/VoidSec/WebRTC-Leak - Third Party Advisory () https://github.com/VoidSec/WebRTC-Leak - Third Party Advisory
References () https://news.ycombinator.com/item?id=16699270 - Issue Tracking () https://news.ycombinator.com/item?id=16699270 - Issue Tracking
References () https://voidsec.com/vpn-leak/ - Third Party Advisory () https://voidsec.com/vpn-leak/ - Third Party Advisory
References () https://www.bleepingcomputer.com/news/security/many-vpn-providers-leak-customers-ip-address-via-webrtc-bug/ - Third Party Advisory () https://www.bleepingcomputer.com/news/security/many-vpn-providers-leak-customers-ip-address-via-webrtc-bug/ - Third Party Advisory

Information

Published : 2018-03-28 21:29

Updated : 2024-11-21 04:10


NVD link : CVE-2018-6608

Mitre link : CVE-2018-6608

CVE.ORG link : CVE-2018-6608


JSON object : View

Products Affected

opera

  • opera_browser
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor