Ubuntu security notices
USN-2955-1: Oxide vulnerabilities
USN-2955-1: Oxide vulnerabilities Ubuntu Security Notice USN-2955-1 27th April, 2016 oxide-qt vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 15.10 Ubuntu 14.04 LTS Summary Several security issues were fixed in Oxide. Software description oxide-qt – Web browser engine for Qt (QML plugin) Details A use-after-free was discovered when responding synchronously topermission requests. An attacker could potentially exploit this to causea denial of service via application crash, or execute arbitrary code withthe privileges of the user invoking the program. (CVE-2016-1578) An out-of-bounds read was discovered in V8. If a user were tricked in toopening a specially crafted website, an attacker could potentially exploitthis to cause a denial of service via renderer crash. (CVE-2016-1646) A use-after-free was discovered in the navigation implementation inChromium in some circumstances. If a user were tricked in to opening [ more… ]