WebKit and LibSoup Vulnerability in Epiphany Browser
CVE-2010-3312
Currently unrated
Summary
The Epiphany web browser versions 2.28 and 2.29 have a vulnerability that results from an unconditional display of a closed-lock icon for all URLs starting with 'https:'. This behavior is misleading as it fails to validate the SSL certificates properly, allowing malicious actors to execute man-in-the-middle attacks. By exploiting this flaw, attackers can spoof legitimate HTTPS websites using crafted X.509 server certificates, putting users' data and communications at risk.
References
Timeline
Vulnerability published
Vulnerability Reserved