Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 511
Alerts This Week
Warning Icon 1 511

Ubuntu 14.04 LTS: USN-2326-1 Moderate: Oxide Use-After-Free Threat

ubuntu
Calendar Grey September 2, 2014
Scroller Ubuntu
Addressed vulnerabilities in Oxide following USN-2326-1 impacting Ubuntu 14.04 LTS, which presented various exploitation paths.
Several security issues were fixed in Oxide.

Summary

Several security issues were fixed in Oxide.

Software Description:

- oxide-qt: Web browser engine library for Qt (QML plugin)

Details:

A use-after-free was discovered in the SVG implementation in Blink. If a

user were tricked in to opening a specially crafted website, an attacker

could potentially exploit this to cause a denial of service via renderer

crash, or execute arbitrary code with the privileges of the sandboxed

render process. (CVE-2014-3168)

A use-after-free was discovered in the DOM implementation in Blink. If a

user were tricked in to opening a specially crafted website, an attacker

could potentially exploit this to cause a denial of service via renderer

crash, or execute arbitrary code with the privileges of the sandboxed

render process. (CVE-2014-3169)

A use-after-free was discovered in V8. If a user were tricked in to

opening a specially crafted website, an attacker could potentially exploit

this to cause a denial of service via renderer cr...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
  liboxideqtcore0                 1.1.2-0ubuntu0.14.04.1
  oxideqt-codecs                  1.1.2-0ubuntu0.14.04.1
  oxideqt-codecs-extra            1.1.2-0ubuntu0.14.04.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2326-1

CVE-2014-3168, CVE-2014-3169, CVE-2014-3171, CVE-2014-3173,

CVE-2014-3174, CVE-2014-3175

Severity
important
Lowest
Low
Medium
High
Critical

September 02, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.