WebKit and LibSoup Vulnerability in Epiphany Browser
CVE-2010-3312

Currently unrated

Key Information:

Vendor
Gnome
Status
Vendor
CVE Published:
14 October 2010

Summary

The Epiphany web browser versions 2.28 and 2.29 have a vulnerability that results from an unconditional display of a closed-lock icon for all URLs starting with 'https:'. This behavior is misleading as it fails to validate the SSL certificates properly, allowing malicious actors to execute man-in-the-middle attacks. By exploiting this flaw, attackers can spoof legitimate HTTPS websites using crafted X.509 server certificates, putting users' data and communications at risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.