Unrated severityNVD Advisory· Published Oct 14, 2010· Updated Apr 29, 2026
CVE-2010-3312
CVE-2010-3312
Description
Epiphany 2.28 and 2.29, when WebKit and LibSoup are used, unconditionally displays a closed-lock icon for any URL beginning with the https: substring, without any warning to the user, which allows man-in-the-middle attackers to spoof arbitrary https web sites via a crafted X.509 server certificate.
Affected products
2cpe:2.3:a:gnome:epiphany:2.28:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:gnome:epiphany:2.28:*:*:*:*:*:*:*
- cpe:2.3:a:gnome:epiphany:2.29:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
15- blog.fefe.denvd
- bugs.debian.org/cgi-bin/bugreport.cginvd
- bugzilla-attachments.gnome.org/attachment.cginvd
- lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlnvd
- secunia.com/advisories/43068nvd
- www.openwall.com/lists/oss-security/2010/09/17/10nvd
- www.openwall.com/lists/oss-security/2010/09/17/12nvd
- www.openwall.com/lists/oss-security/2010/09/17/13nvd
- www.openwall.com/lists/oss-security/2010/09/17/5nvd
- www.openwall.com/lists/oss-security/2010/09/17/6nvd
- www.openwall.com/lists/oss-security/2010/09/20/2nvd
- www.openwall.com/lists/oss-security/2010/09/21/5nvd
- www.vupen.com/english/advisories/2011/0212nvd
- bugzilla.gnome.org/show_bug.cginvd
News mentions
0No linked articles in our index yet.