In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for a UTF-8 ellipsis character is not properly considered.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade epiphany | Aug 22, 2024 | Apr 20, 2022 |
| Debian | — | Upgrade epiphany-browser | Aug 19, 2022 | Apr 20, 2022 |
| Gentoo Linux | — | Upgrade www-client/epiphany. | May 10, 2024 | Apr 20, 2022 |
| Ubuntu | — | Upgrade epiphany-browser | Aug 11, 2022 | Apr 20, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub