RULE(RULE ID:323875)

Rule General Information
Release Date: 2019-11-29
Rule Name: HTTP Client LAN IP Address Gather Vulnerability (CVE-2018-6849)
Severity:
CVE ID:
Rule Protection Details
Description: In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), the browser can disclose a private IP address in a STUN request.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Others
Reference: ExploitDB:44403
https://datarift.blogspot.com/p/private-ip-leakage-using-webrtc.html
https://github.com/rapid7/metasploit-framework/pull/9538
https://news.ycombinator.com/item?id=16699270
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://duckduckgo.com/