Advisories ยป MGASA-2022-0382

Updated epiphany packages fix security vulnerability

Publication date: 23 Oct 2022
Modification date: 23 Oct 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-29536

Description

In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can
trigger a client buffer overflow (in ephy_string_shorten in the UI
process) via a long page title. The issue occurs because the number of
bytes for a UTF-8 ellipsis character is not properly considered.
(CVE-2022-29536)
                

References

SRPMS

8/core