vendor:
Web (aka Epiphany)
by:
N/A
7.5
CVSS
HIGH
Denial of Service
20
CWE
Product Name: Web (aka Epiphany)
Affected Version From: 3.28.2.1
Affected Version To: 3.28.2.1
Patch Exists: YES
Related CWE: CVE-2018-11396
CPE: N/A
Platforms Tested: N/A
2018
ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 Denial of Service Vulnerability
ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that triggers access to a NULL URL, as demonstrated by a crafted window.open call.
Mitigation:
Ensure that the application is updated to the latest version of GNOME Web (aka Epiphany) 3.28.2.1 or later.