CVE-2018-12016: High severity gnome epiphany vulnerability
Published Jun 7, 2018
·Updated
libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via certain window.open and document.write calls.
Affected Software
1 affected component
Gnome Epiphany<=3.28.2.1
Event History
Jun 7, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-12016.
2
What is the severity of CVE-2018-12016?
The severity of CVE-2018-12016 is high with a CVSS score of 7.5.
3
What is the affected software?
The affected software is GNOME Epiphany through version 3.28.2.1.
4
How can remote attackers exploit CVE-2018-12016?
Remote attackers can cause a denial of service (application crash) by exploiting certain window.open and document.write calls.
5
Is there any additional reference for this vulnerability?
Yes, you can find additional information about CVE-2018-12016 at this link: [https://github.com/ldpreload/Disclosure/blob/master/EpiphanyDoS.txt](https://github.com/ldpreload/Disclosure/blob/master/EpiphanyDoS.txt).