Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Ubuntu 15.04 USN-2770-1 Critical: Oxide-QT Security Flaws

ubuntu
Calendar Grey October 20, 2015
Scroller Ubuntu
A number of vital concerns in oxide-qt have been resolved to safeguard Ubuntu users from potential security vulnerabilities.
Several security issues were fixed in Oxide.

Summary

Several security issues were fixed in Oxide.

Software Description:

- oxide-qt: Web browser engine library for Qt (QML plugin)

Details:

It was discovered that ContainerNode::parserInsertBefore in Blink would

incorrectly proceed with a DOM tree insertion in some circumstances. If a

user were tricked in to opening a specially crafted website, an attacker

could potentially exploit this to bypass same origin restrictions.

(CVE-2015-6755)

A use-after-free was discovered in the service worker implementation in

Chromium. If a user were tricked in to opening a specially crafted

website, an attacker could potentially exploit this to cause a denial of

service via application crash, or execute arbitrary code with the

privileges of the user invoking the program. (CVE-2015-6757)

It was discovered that Blink did not ensure that the origin of

LocalStorage resources are considered unique. If a user were tricked in to

opening a specially crafted website, an attacker could ...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.04:
  liboxideqtcore0                 1.10.3-0ubuntu0.15.04.1

Ubuntu 14.04 LTS:
  liboxideqtcore0                 1.10.3-0ubuntu0.14.04.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2770-1

CVE-2015-6755, CVE-2015-6757, CVE-2015-6759, CVE-2015-6761,

CVE-2015-6762, CVE-2015-6763, CVE-2015-7834

Severity
critical
Lowest
Low
Medium
High
Critical

October 20, 2015

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.