Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Mageia 8 MGASA-2023-0099 Critical: Epiphany Exfiltration Threat

mageia
Calendar Grey March 18, 2023
Dist Mageia Esm H88
Mageia 2023-0100 resolves a vulnerability in Firefox, stopping unauthorized credential extraction via malicious scripts.
In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts

Summary

In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts. (CVE-2023-26081)

References

- https://bugs.mageia.org/show_bug.cgi?id=31609

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/SADQCSQKTJKTTIJMEPY7GII6IVQSKEKV/

- https://www.cve.org/CVERecord?id=CVE-2023-26081

Resolution

SRPMS

- 8/core/epiphany-3.38.2-1.3.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 18 Mar 2023
URL: https://advisories.mageia.org/MGASA-2023-0099.html
Type: security
CVE: CVE-2023-26081

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here