In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for a UTF-8 ellipsis character is not properly considered.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-epiphany | Aug 22, 2024 | Apr 20, 2022 | |
| Debian | debian-upgrade-epiphany-browser | Aug 19, 2022 | Apr 20, 2022 | |
| Gentoo Linux | gentoo-linux-upgrade-www-client-epiphany | May 10, 2024 | Apr 20, 2022 | |
| Ubuntu | ubuntu-upgrade-epiphany-browser | Aug 11, 2022 | Apr 20, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub