Epiphany: Untrusted search path An untrusted search path vulnerability in Epiphany might result in the execution of arbitrary code. epiphany 2009-03-09 2009-03-09 257000 local 2.22.3-r2 2.22.3-r2

Epiphany is a GNOME webbrowser based on the Mozilla rendering engine Gecko.

James Vega reported an untrusted search path vulnerability in the Python interface.

A local attacker could entice a user to run Epiphany from a directory containing a specially crafted python module, resulting in the execution of arbitrary code with the privileges of the user running Epiphany.

Do not run "epiphany" from untrusted working directories.

All Epiphany users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=www-client/epiphany-2.22.3-r2"
CVE-2008-5985 rbu rbu rbu