Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Ubuntu 14.04 & 15.04: Security Advisory for Oxide Web Engine

ubuntu
Calendar Grey October 5, 2015
Scroller Ubuntu
Recent updates to Oxide in Ubuntu versions 14.04 and 15.04 have resolved two significant vulnerabilities, effectively mitigating serious security risks.
Several security issues were fixed in Oxide.

Summary

Several security issues were fixed in Oxide.

Software Description:

- oxide-qt: Web browser engine library for Qt (QML plugin)

Details:

Two security issues were discovered in Blink and V8. If a user were

tricked in to opening a specially crafted website, an attacker could

potentially exploit these to bypass same-origin restrictions.

(CVE-2015-1303, CVE-2015-1304)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.04:
  liboxideqtcore0                 1.9.5-0ubuntu0.15.04.1

Ubuntu 14.04 LTS:
  liboxideqtcore0                 1.9.5-0ubuntu0.14.04.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2757-1

CVE-2015-1303, CVE-2015-1304

Severity
important
Lowest
Low
Medium
High
Critical

October 05, 2015

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.