Epiphany: Untrusted search path An untrusted search path vulnerability in Epiphany might result in the execution of arbitrary code. epiphany March 09, 2009 March 09, 2009: 01 257000 local 2.22.3-r2 2.22.3-r2

Epiphany is a GNOME webbrowser based on the Mozilla rendering engine Gecko.

James Vega reported an untrusted search path vulnerability in the Python interface.

A local attacker could entice a user to run Epiphany from a directory containing a specially crafted python module, resulting in the execution of arbitrary code with the privileges of the user running Epiphany.

Do not run "epiphany" from untrusted working directories.

All Epiphany users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=www-client/epiphany-2.22.3-r2"
CVE-2008-5985 rbu rbu rbu