Bug#528071: epiphany-browser: Runs google websearch on bad addresses. not configurable, possible information leakage

Witold Baryluk baryluk at smp.if.uj.edu.pl
Sun May 10 16:17:39 UTC 2009


Subject: epiphany-browser: Runs google websearch on bad addresses. not configurable, possible information leakage
Package: epiphany-browser
Version: 2.26.1-1
Severity: important

What was my surprise when after some small typo error epiphany browser
automatically redirected me to the google websearch.

I'm using epiphany especially because i was considering it safe and simple.

This episode is changing my opinion in this matter.

If any such functionality was added, can it be disabled (with predefined error message,
as it was before), or redirect to some other webpage (%s can be urlencoded text which
was in address bar)?

I also noticed that after entering some text in address bar, beside history of my browser,
on the bottom I see "Debian Bug Tracking System " and "Przeszukiwanie sieci WWW" (in polish,
"Searching WWW Net"). "Of course" last one is google web search.

Is this hardcoded configuration? I searched for it but failed.

Regards,
Witold Baryluk

-- System Information:
Debian Release: squeeze/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.30-rc5-00000-rc5 (PREEMPT)
Locale: LANG=pl_PL.UTF-8, LC_CTYPE=pl_PL.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages epiphany-browser depends on:
ii  epiphany-gecko                2.26.1-1   Intuitive GNOME web browser - Geck

epiphany-browser recommends no packages.

epiphany-browser suggests no packages.

Versions of packages epiphany-gecko depends on:
ii  dbus-x11                    1.2.14-2     simple interprocess messaging syst
ii  epiphany-browser-data       2.26.1-1     Data files for the GNOME web brows
ii  gnome-icon-theme            2.24.0-4     GNOME Desktop icon theme
ii  iso-codes                   3.9-1        ISO language, territory, currency,
ii  libavahi-client3            0.6.25-1     Avahi client library
ii  libavahi-common3            0.6.25-1     Avahi common library
ii  libavahi-gobject0           0.6.25-1     Avahi GObject library
ii  libc6                       2.9-12       GNU C Library: Shared libraries
ii  libcanberra-gtk0            0.11-1       Gtk+ helper for playing widget eve
ii  libcanberra0                0.11-1       a simple abstract interface for pl
ii  libdbus-1-3                 1.2.14-2     simple interprocess messaging syst
ii  libdbus-glib-1-2            0.80-4       simple interprocess messaging syst
ii  libenchant1c2a              1.4.2-3.3    a wrapper library for various spel
ii  libgcc1                     1:4.4.0-4    GCC support library
ii  libgconf2-4                 2.26.0-1     GNOME configuration database syste
ii  libglade2-0                 1:2.6.4-1    library to load .glade files at ru
ii  libglib2.0-0                2.20.1-2     The GLib library of C routines
ii  libgnome2-0                 2.26.0-1     The GNOME library - runtime files
ii  libgnomeui-0                2.24.1-1     The GNOME 2 libraries (User Interf
ii  libgtk2.0-0                 2.16.1-2     The GTK+ graphical user interface 
ii  libnotify1 [libnotify1-gtk2 0.4.5-1      sends desktop notifications to a n
ii  libnspr4-0d                 4.7.4-2      NetScape Portable Runtime Library
ii  libpango1.0-0               1.24.0-3+b1  Layout and rendering of internatio
ii  libstdc++6                  4.4.0-4      The GNU Standard C++ Library v3
ii  libx11-6                    2:1.2.1-1    X11 client-side library
ii  libxml2                     2.7.3.dfsg-1 GNOME XML library
ii  libxslt1.1                  1.1.24-2     XSLT processing library - runtime 
ii  python2.5                   2.5.4-1      An interactive high-level object-o
ii  xulrunner-1.9               1.9.0.10-1   XUL + XPCOM application runner
ii  xulrunner-1.9-gnome-support 1.9.0.10-1   Support for GNOME in xulrunner app

-- no debconf information


-- 
Witold Baryluk
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 197 bytes
Desc: To jest cz??? wiadomo?ci podpisana cyfrowo
URL: <http://lists.alioth.debian.org/pipermail/pkg-gnome-maintainers/attachments/20090510/3c8961ad/attachment.pgp>


More information about the pkg-gnome-maintainers mailing list