Debian Bug report logs - #528071
epiphany-browser: Runs google websearch on bad addresses. not configurable, possible information leakage

version graph

Package: epiphany-browser; Maintainer for epiphany-browser is Debian GNOME Maintainers <pkg-gnome-maintainers@lists.alioth.debian.org>; Source for epiphany-browser is src:epiphany-browser (PTS, buildd, popcon).

Reported by: Witold Baryluk <baryluk@smp.if.uj.edu.pl>

Date: Sun, 10 May 2009 16:21:01 UTC

Severity: normal

Found in versions epiphany-browser/2.26.1-1, epiphany-browser/2.30.2-1

Done: Jeremy Bícha <jbicha@debian.org>

Bug is archived. No further changes may be made.

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Josselin Mouette <joss@debian.org>:
Bug#528071; Package epiphany-browser. (Sun, 10 May 2009 16:21:04 GMT) (full text, mbox, link).


Acknowledgement sent to Witold Baryluk <baryluk@smp.if.uj.edu.pl>:
New Bug report received and forwarded. Copy sent to Josselin Mouette <joss@debian.org>. (Sun, 10 May 2009 16:21:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Witold Baryluk <baryluk@smp.if.uj.edu.pl>
To: submit@bugs.debian.org
Subject: epiphany-browser: Runs google websearch on bad addresses. not configurable, possible information leakage
Date: Sun, 10 May 2009 18:17:39 +0200
[Message part 1 (text/plain, inline)]
Subject: epiphany-browser: Runs google websearch on bad addresses. not configurable, possible information leakage
Package: epiphany-browser
Version: 2.26.1-1
Severity: important

What was my surprise when after some small typo error epiphany browser
automatically redirected me to the google websearch.

I'm using epiphany especially because i was considering it safe and simple.

This episode is changing my opinion in this matter.

If any such functionality was added, can it be disabled (with predefined error message,
as it was before), or redirect to some other webpage (%s can be urlencoded text which
was in address bar)?

I also noticed that after entering some text in address bar, beside history of my browser,
on the bottom I see "Debian Bug Tracking System " and "Przeszukiwanie sieci WWW" (in polish,
"Searching WWW Net"). "Of course" last one is google web search.

Is this hardcoded configuration? I searched for it but failed.

Regards,
Witold Baryluk

-- System Information:
Debian Release: squeeze/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.30-rc5-00000-rc5 (PREEMPT)
Locale: LANG=pl_PL.UTF-8, LC_CTYPE=pl_PL.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages epiphany-browser depends on:
ii  epiphany-gecko                2.26.1-1   Intuitive GNOME web browser - Geck

epiphany-browser recommends no packages.

epiphany-browser suggests no packages.

Versions of packages epiphany-gecko depends on:
ii  dbus-x11                    1.2.14-2     simple interprocess messaging syst
ii  epiphany-browser-data       2.26.1-1     Data files for the GNOME web brows
ii  gnome-icon-theme            2.24.0-4     GNOME Desktop icon theme
ii  iso-codes                   3.9-1        ISO language, territory, currency,
ii  libavahi-client3            0.6.25-1     Avahi client library
ii  libavahi-common3            0.6.25-1     Avahi common library
ii  libavahi-gobject0           0.6.25-1     Avahi GObject library
ii  libc6                       2.9-12       GNU C Library: Shared libraries
ii  libcanberra-gtk0            0.11-1       Gtk+ helper for playing widget eve
ii  libcanberra0                0.11-1       a simple abstract interface for pl
ii  libdbus-1-3                 1.2.14-2     simple interprocess messaging syst
ii  libdbus-glib-1-2            0.80-4       simple interprocess messaging syst
ii  libenchant1c2a              1.4.2-3.3    a wrapper library for various spel
ii  libgcc1                     1:4.4.0-4    GCC support library
ii  libgconf2-4                 2.26.0-1     GNOME configuration database syste
ii  libglade2-0                 1:2.6.4-1    library to load .glade files at ru
ii  libglib2.0-0                2.20.1-2     The GLib library of C routines
ii  libgnome2-0                 2.26.0-1     The GNOME library - runtime files
ii  libgnomeui-0                2.24.1-1     The GNOME 2 libraries (User Interf
ii  libgtk2.0-0                 2.16.1-2     The GTK+ graphical user interface 
ii  libnotify1 [libnotify1-gtk2 0.4.5-1      sends desktop notifications to a n
ii  libnspr4-0d                 4.7.4-2      NetScape Portable Runtime Library
ii  libpango1.0-0               1.24.0-3+b1  Layout and rendering of internatio
ii  libstdc++6                  4.4.0-4      The GNU Standard C++ Library v3
ii  libx11-6                    2:1.2.1-1    X11 client-side library
ii  libxml2                     2.7.3.dfsg-1 GNOME XML library
ii  libxslt1.1                  1.1.24-2     XSLT processing library - runtime 
ii  python2.5                   2.5.4-1      An interactive high-level object-o
ii  xulrunner-1.9               1.9.0.10-1   XUL + XPCOM application runner
ii  xulrunner-1.9-gnome-support 1.9.0.10-1   Support for GNOME in xulrunner app

-- no debconf information


-- 
Witold Baryluk
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, Josselin Mouette <joss@debian.org>:
Bug#528071; Package epiphany-browser. (Sun, 10 May 2009 16:33:04 GMT) (full text, mbox, link).


Acknowledgement sent to Witold Baryluk <baryluk@smp.if.uj.edu.pl>:
Extra info received and forwarded to list. Copy sent to Josselin Mouette <joss@debian.org>. (Sun, 10 May 2009 16:33:04 GMT) (full text, mbox, link).


Message #10 received at 528071@bugs.debian.org (full text, mbox, reply):

From: Witold Baryluk <baryluk@smp.if.uj.edu.pl>
To: 528071@bugs.debian.org
Subject: epihany-browser: default websearch
Date: Sun, 10 May 2009 18:31:40 +0200
[Message part 1 (text/plain, inline)]
severity 528071 normal
stop

Ok, after some more testing I found two things:

1. In about:config i can disable keyword.enable and/or change
keyword.URL.

Still after disabling epiphany is trying to load url, in example
just appending .com to it.

2. Additional entries in addressbar are accessible using magic in
bookmarks (any entry with url containing %s is treated as additional
entry for addressbar).


Because of this, I lowering severity. Anyway still I'm thinking that
this should be easier to configure. :)


-- 
Witold Baryluk

[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, Josselin Mouette <joss@debian.org>:
Bug#528071; Package epiphany-browser. (Sun, 16 Aug 2009 07:48:02 GMT) (full text, mbox, link).


Acknowledgement sent to 528071@bugs.debian.org:
Extra info received and forwarded to list. Copy sent to Josselin Mouette <joss@debian.org>. (Sun, 16 Aug 2009 07:48:02 GMT) (full text, mbox, link).


Message #15 received at 528071@bugs.debian.org (full text, mbox, reply):

From: Josselin Mouette <joss@debian.org>
To: Witold Baryluk <baryluk@smp.if.uj.edu.pl>, 528071@bugs.debian.org
Subject: Re: Bug#528071: epihany-browser: default websearch
Date: Sun, 16 Aug 2009 09:45:39 +0200
[Message part 1 (text/plain, inline)]
severity 528071 normal
stop

Le dimanche 10 mai 2009 à 18:31 +0200, Witold Baryluk a écrit :
> Ok, after some more testing I found two things:
> 
> 1. In about:config i can disable keyword.enable and/or change
> keyword.URL.
> 
> Still after disabling epiphany is trying to load url, in example
> just appending .com to it.

> Because of this, I lowering severity. Anyway still I'm thinking that
> this should be easier to configure. :)

I’m the first one to be annoyed by this behavior and I have disabled it
on my systems. However the bottom line is simple: disable this crap by
default, and you’ll get tons of complaints.

Cheers,
-- 
 .''`.      Josselin Mouette
: :' :
`. `'   “I recommend you to learn English in hope that you in
  `-     future understand things”  -- Jörg Schilling
[signature.asc (application/pgp-signature, inline)]

Severity set to 'normal' from 'important' Request was from Josselin Mouette <joss@debian.org> to control@bugs.debian.org. (Sun, 16 Aug 2009 07:48:04 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Josselin Mouette <joss@debian.org>:
Bug#528071; Package epiphany-browser. (Sat, 15 May 2010 09:57:06 GMT) (full text, mbox, link).


Acknowledgement sent to intrigeri@boum.org:
Extra info received and forwarded to list. Copy sent to Josselin Mouette <joss@debian.org>. (Sat, 15 May 2010 09:57:06 GMT) (full text, mbox, link).


Message #22 received at 528071@bugs.debian.org (full text, mbox, reply):

From: intrigeri@boum.org
To: control@bugs.debian.org, 528071@bugs.debian.org
Subject: affected version
Date: Sat, 15 May 2010 11:53:28 +0200
found 528071 2.30.2-1
thanks

I could not find any way to customize the default search engine in 2.30.2-1.

Bye,
-- 
  intrigeri <intrigeri@boum.org>




Bug Marked as found in versions epiphany-browser/2.30.2-1. Request was from intrigeri@boum.org to control@bugs.debian.org. (Sat, 15 May 2010 09:57:09 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Josselin Mouette <joss@debian.org>:
Bug#528071; Package epiphany-browser. (Sat, 15 May 2010 10:03:03 GMT) (full text, mbox, link).


Acknowledgement sent to intrigeri <intrigeri@boum.org>:
Extra info received and forwarded to list. Copy sent to Josselin Mouette <joss@debian.org>. (Sat, 15 May 2010 10:03:03 GMT) (full text, mbox, link).


Message #29 received at 528071@bugs.debian.org (full text, mbox, reply):

From: intrigeri <intrigeri@boum.org>
To: 528071@bugs.debian.org
Subject: Re: Bug#528071: affected version
Date: Sat, 15 May 2010 12:00:52 +0200
intrigeri@boum.org wrote (15 May 2010 09:53:28 GMT) :
> I could not find any way to customize the default search engine in
> 2.30.2-1.

I was wrong: the /apps/epiphany/general/url_search GConf key allows
to customize the default search engine.

Bye,
--
  intrigeri <intrigeri@boum.org>
  | GnuPG key @ https://gaffer.ptitcanardnoir.org/intrigeri/intrigeri.asc
  | OTR fingerprint @ https://gaffer.ptitcanardnoir.org/intrigeri/otr-fingerprint.asc
  | We're dreaming of something else.
  | Something more clandestine, something happier.




Reply sent to Jeremy Bícha <jbicha@debian.org>:
You have taken responsibility. (Sun, 09 Nov 2025 23:41:05 GMT) (full text, mbox, link).


Notification sent to Witold Baryluk <baryluk@smp.if.uj.edu.pl>:
Bug acknowledged by developer. (Sun, 09 Nov 2025 23:41:05 GMT) (full text, mbox, link).


Message #34 received at 528071-done@bugs.debian.org (full text, mbox, reply):

From: Jeremy Bícha <jbicha@debian.org>
To: 472386-done@bugs.debian.org, 504984-done@bugs.debian.org, 516490-done@bugs.debian.org, 517773-done@bugs.debian.org, 523993-done@bugs.debian.org, 525456-done@bugs.debian.org, 526958-done@bugs.debian.org, 528071-done@bugs.debian.org, 690661-done@bugs.debian.org, 531342-done@bugs.debian.org, 544287-done@bugs.debian.org, 548368-done@bugs.debian.org, 548374-done@bugs.debian.org, 548396-done@bugs.debian.org, 548422-done@bugs.debian.org, 550144-done@bugs.debian.org, 550515-done@bugs.debian.org, 552607-done@bugs.debian.org, 555108-done@bugs.debian.org, 555770-done@bugs.debian.org
Subject: closing ancient epiphany-browser bugs
Date: Sun, 9 Nov 2025 18:39:32 -0500
There have been many changes to Debian since this bug was originally
reported. If you are still experiencing this issue with Debian 13 (or
with Debian 12 or Testing or Unstable), please report a new bug.

Thank you,
Jeremy Bícha



Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Mon, 08 Dec 2025 07:45:26 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Fri Jan 23 19:35:01 2026; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU General Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.