In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephystringshorten in the UI process) via a long page title. The issue occurs because the number of bytes for a UTF-8 ellipsis character is not properly considered.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "3.36.4-0ubuntu2", "binary_name": "epiphany-browser" }, { "binary_version": "3.36.4-0ubuntu2", "binary_name": "epiphany-browser-data" }, { "binary_version": "3.36.4-0ubuntu2", "binary_name": "epiphany-browser-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "42.1-1ubuntu1", "binary_name": "epiphany-browser" }, { "binary_version": "42.1-1ubuntu1", "binary_name": "epiphany-browser-data" }, { "binary_version": "42.1-1ubuntu1", "binary_name": "epiphany-browser-dbgsym" } ] }