CVE-2018-11396: High severity gnome epiphany vulnerability
ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that triggers access to a NULL URL, as demonstrated by a crafted window.open call.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11396?
CVE-2018-11396 is a vulnerability in GNOME Web (aka Epiphany) through version 3.28.2.1 that allows remote attackers to cause a denial of service (application crash) via crafted JavaScript code.
How does CVE-2018-11396 affect GNOME Web?
CVE-2018-11396 affects GNOME Web (aka Epiphany) version 3.28.2.1 and earlier.
What is the severity of CVE-2018-11396?
CVE-2018-11396 has a severity level of high (CVSS score of 7.5).
How can CVE-2018-11396 be exploited?
CVE-2018-11396 can be exploited by remote attackers using crafted JavaScript code.
Is there a fix available for CVE-2018-11396?
Yes, a fix for CVE-2018-11396 is available. Users should update to a version of GNOME Web (aka Epiphany) that is later than 3.28.2.1.