Vulnerability Description
GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resulting in the remote exfiltration of stored passwords for a selected set of websites.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Epiphany | 3.18.0 |
Related Weaknesses (CWE)
References
- https://bugzilla.gnome.org/show_bug.cgi?id=752738Issue TrackingVendor Advisory
- https://www.usenix.org/conference/usenixsecurity14/technical-sessions/presentatiTechnical DescriptionThird Party Advisory
- https://bugzilla.gnome.org/show_bug.cgi?id=752738Issue TrackingVendor Advisory
- https://www.usenix.org/conference/usenixsecurity14/technical-sessions/presentatiTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2017-1000025?
CVE-2017-1000025 is a vulnerability with a CVSS score of 7.5 (HIGH). GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resulting in the remote exfil...
How severe is CVE-2017-1000025?
CVE-2017-1000025 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-1000025?
Check the references section above for vendor advisories and patch information. Affected products include: Gnome Epiphany.