Unrated severityOSV Advisory· Published Apr 1, 2018· Updated Aug 5, 2024
CVE-2018-6849
CVE-2018-6849
Description
In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), the browser can disclose a private IP address in a STUN request.
Affected products
1- Range: 0.1.0, 0.10.0, 0.2.0, …
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.exploit-db.com/exploits/44403/mitreexploitx_refsource_EXPLOIT-DB
- datarift.blogspot.com/p/private-ip-leakage-using-webrtc.htmlmitrex_refsource_MISC
- github.com/rapid7/metasploit-framework/pull/9538mitrex_refsource_MISC
- news.ycombinator.com/itemmitrex_refsource_MISC
- voidsec.com/vpn-leak/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.