Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 8: 2022-0382 Moderate: Epiphany Buffer Overflow Fix

mageia
Calendar Grey October 23, 2022
Dist Mageia Esm H88
Newly released Epiphany updates address critical buffer overflow vulnerabilities in Mageia. Discover the specifics of the security enhancements and the updates involved.
In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title

Summary

In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for a UTF-8 ellipsis character is not properly considered. (CVE-2022-29536)

References

- https://bugs.mageia.org/show_bug.cgi?id=30365

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/GLLDMY4JYDZTMZSCPSY23K5YW3SQYUR6/

-

- https://lists.debian.org/debian-security-announce/2022/msg00177.html

- https://www.cve.org/CVERecord?id=CVE-2022-29536

Resolution

SRPMS

- 8/core/epiphany-3.38.2-1.2.mga8

Publication date: 23 Oct 2022
URL: https://advisories.mageia.org/MGASA-2022-0382.html
Type: security
CVE: CVE-2022-29536

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here