Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in Oxide.
Software Description:
- oxide-qt: Web browser engine library for Qt
Details:
A type confusion bug was discovered in V8. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-1730)
A type confusion bug was discovered in Blink. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-1731)
Multiple security issues including memory safety bugs were discovered in
Chromium. If a user were tricked in to opening a specially crafted website,
an attacker could potentially exploit these to cause a denial of service via
application crash or execut...
The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: liboxideqtcore0 1.0.4-0ubuntu0.14.04.1 oxideqt-codecs 1.0.4-0ubuntu0.14.04.1 oxideqt-codecs-extra 1.0.4-0ubuntu0.14.04.1 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-2298-1
CVE-2014-1730, CVE-2014-1731, CVE-2014-1735, CVE-2014-1740,
CVE-2014-1741, CVE-2014-1742, CVE-2014-1743, CVE-2014-1744,
CVE-2014-1746, CVE-2014-1748, CVE-2014-3152, CVE-2014-3154,
CVE-2014-3155, CVE-2014-3157, CVE-2014-3160, CVE-2014-3162,
CVE-2014-3803, https://bugs.launchpad.net/ubuntu/+source/oxide-qt/+bug/1337301
Get the latest Linux and open source security news straight to your inbox.