Description
In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for a UTF-8 ellipsis character is not properly considered.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3074-1 | epiphany-browser security update |
Debian DSA |
DSA-5208-1 | epiphany-browser security update |
EUVD |
EUVD-2022-33872 | In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for a UTF-8 ellipsis character is not properly considered. |
Ubuntu USN |
USN-5561-1 | GNOME Web vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T06:26:06.251Z
Reserved: 2022-04-20T00:00:00.000Z
Link: CVE-2022-29536
No data.
Status : Modified
Published: 2022-04-20T23:15:08.733
Modified: 2024-11-21T06:59:17.080
Link: CVE-2022-29536
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN