CVE-2022-29536: Buffer Overflow
In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephystringshorten in the UI process) via a long page title. The issue occurs because the number of bytes for a UTF-8 ellipsis character is not properly considered.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-29536?
CVE-2022-29536 is a vulnerability in GNOME Epiphany that allows an HTML document to trigger a client buffer overflow via a long page title.
What is the severity of CVE-2022-29536?
CVE-2022-29536 has a severity rating of 7.5 (high).
How does CVE-2022-29536 affect Epiphany?
CVE-2022-29536 affects Epiphany versions before 41.4 and 42.x before 42.2.
What is the impact of CVE-2022-29536?
CVE-2022-29536 allows an attacker to trigger a client buffer overflow, potentially leading to remote code execution.
How can I mitigate CVE-2022-29536?
To mitigate CVE-2022-29536, it is recommended to update Epiphany to version 41.4 or 42.2 or later.