Hide Forgot
A flaw was found in ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that triggers access to a NULL URL, as demonstrated by a crafted window.open call. References: https://bugzilla.gnome.org/show_bug.cgi?id=795740 Upstream Patch: https://bug795740.bugzilla-attachments.gnome.org/attachment.cgi?id=372352
Created epiphany tracking bugs for this issue: Affects: fedora-all [bug 1581802]
*** Bug 1588759 has been marked as a duplicate of this bug. ***
*** Bug 1588757 has been marked as a duplicate of this bug. ***
Update prepared in bug #1581802.