An update for epiphany is now available for openEuler-22.03-LTS
Security Advisory
openeuler-security@openeuler.org
openEuler security committee
openEuler-SA-2023-1139
Final
1.0
1.0
2023-03-04
Initial
2023-03-04
2023-03-04
openEuler SA Tool V1.0
2023-03-04
epiphany security update
An update for epiphany is now available for openEuler-22.03-LTS.
Epiphany is the web browser for the GNOME desktop. Its goal is to be simple and easy to use. Epiphany ties together many GNOME components in order to let you focus on the Web content, instead of the browser application.
Security Fix(es):
In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.(CVE-2023-26081)
An update for epiphany is now available for openEuler-22.03-LTS.
openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.
High
epiphany
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1139
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2023-26081
https://nvd.nist.gov/vuln/detail/CVE-2023-26081
openEuler-22.03-LTS
epiphany-debuginfo-40.6-3.oe2203.aarch64.rpm
epiphany-debugsource-40.6-3.oe2203.aarch64.rpm
epiphany-runtime-40.6-3.oe2203.aarch64.rpm
epiphany-40.6-3.oe2203.aarch64.rpm
epiphany-40.6-3.oe2203.src.rpm
epiphany-debuginfo-40.6-3.oe2203.x86_64.rpm
epiphany-debugsource-40.6-3.oe2203.x86_64.rpm
epiphany-40.6-3.oe2203.x86_64.rpm
epiphany-runtime-40.6-3.oe2203.x86_64.rpm
In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.
2023-03-04
CVE-2023-26081
openEuler-22.03-LTS
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
epiphany security update
2023-03-04
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1139