UBUNTU-CVE-2011-4692

Source
https://ubuntu.com/security/CVE-2011-4692
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2011/UBUNTU-CVE-2011-4692.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2011-4692
Upstream
  • CVE-2011-4692
Published
2011-12-07T19:55:00Z
Modified
2025-10-24T04:44:55Z
Severity
  • Ubuntu - low
Summary
[none]
Details

WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 and earlier, does not prevent capture of data about the time required for image loading, which makes it easier for remote attackers to determine whether an image exists in the browser cache via crafted JavaScript code, as demonstrated by visipisi.

References

Affected packages

Ubuntu:16.04:LTS / qtwebkit-source

Package

Name
qtwebkit-source
Purl
pkg:deb/ubuntu/qtwebkit-source@2.3.2-0ubuntu11?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.3.2-0ubuntu10
2.3.2-0ubuntu11

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.3.2-0ubuntu11",
            "binary_name": "libqtwebkit-dev"
        },
        {
            "binary_version": "2.3.2-0ubuntu11",
            "binary_name": "libqtwebkit-qmlwebkitplugin"
        },
        {
            "binary_version": "2.3.2-0ubuntu11",
            "binary_name": "libqtwebkit4"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2011/UBUNTU-CVE-2011-4692.json"