Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
172

Ubuntu 16.10: USN-3236-1 Moderate: Oxide Security Update

Several security issues were fixed in Oxide.. =========================================================================Ubuntu Security Notice USN-3236-1 March 29, 2017 oxide-qt vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.10 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Oxide. Software Description: - oxide-qt: Web browser engine for Qt (QML plugin) Details: Multiple vulnerabilities were discovered in Chromium. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to obtain sensitive information, spoof application UI by causing the security status API or webview URL to indicate the wrong values, bypass security restrictions, cause a denial of service via application crash, or execute arbitrary code. (CVE-2017-5029, CVE-2017-5030, CVE-2017-5031, CVE-2017-5033, CVE-2017-5035, CVE-2017-5037, CVE-2017-5040, CVE-2017-5041, CVE-2017-5044, CVE-2017-5045, CVE-2017-5046) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.10: liboxideqtcore0 1.21.5-0ubuntu0.16.10.1 Ubuntu 16.04 LTS: liboxideqtcore0 1.21.5-0ubuntu0.16.04.1 Ubuntu 14.04 LTS: liboxideqtcore0 1.21.5-0ubuntu0.14.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3236-1 CVE-2017-5029, CVE-2017-5030, CVE-2017-5031, CVE-2017-5033, CVE-2017-5035, CVE-2017-5037, CVE-2017-5040, CVE-2017-5041, CVE-2017-5044, CVE-2017-5045, CVE-2017-5046 Package Information: https://launchpad.net/ubuntu/+source/oxide-qt/1.21.5-0ubuntu0.16.10.1 https://launchpad.net/ubuntu/+source/oxide-qt/1.21.5-0ubuntu0.16.04.1 https://launchpad.net/ubuntu/+source/oxide-qt/1.21.5-0ubuntu0.14.04.1 . Several vulnerabilities in Oxide have been resolved in Ubuntu versions 16.10, 16.04 LTS, and 14.04 LTS. Ensure your system is secure!. Oxide Qt Libraries, Ubuntu Security, Application Crash, Web Browser Engine. . LinuxSecurity.com Team

Calendar%202 Mar 29, 2017 Ubuntu
172

Ubuntu 16.10: USN-3113-1 Critical: Oxide Weaknesses Disclosed

Several security issues were fixed in Oxide.. =========================================================================Ubuntu Security Notice USN-3113-1 November 02, 2016 oxide-qt vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.10 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Oxide. Software Description: - oxide-qt: Web browser engine for Qt (QML plugin) Details: It was discovered that a long running unload handler could cause an incognito profile to be reused in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to obtain sensitive information. (CVE-2016-1586) Multiple security vulnerabilities were discovered in Chromium. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to conduct cross-site scripting (XSS) attacks, spoof an application's URL bar, obtain sensitive information, cause a denial of service via application crash, or execute arbitrary code. (CVE-2016-5181, CVE-2016-5182, CVE-2016-5185, CVE-2016-5186, CVE-2016-5187, CVE-2016-5188, CVE-2016-5189, CVE-2016-5192, CVE-2016-5194) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.10: liboxideqtcore0 1.18.3-0ubuntu0.16.10.1 Ubuntu 16.04 LTS: liboxideqtcore0 1.18.3-0ubuntu0.16.04.1 Ubuntu 14.04 LTS: liboxideqtcore0 1.18.3-0ubuntu0.14.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3113-1 CVE-2016-1586, CVE-2016-5181, CVE-2016-5182, CVE-2016-5185, CVE-2016-5186, CVE-2016-5187, CVE-2016-5188, CVE-2016-5189, CVE-2016-5192, CVE-2016-5194 Package Information: https://launchpad.net/ubuntu/+source/oxide-qt/1.18.3-0ubuntu0.16.10.1 https://launchpad.net/ubuntu/+source/oxide-qt/1.18.3-0ubuntu0.16.04.1 https://launchpad.net/ubuntu/+source/oxide-qt/1.18.3-0ubuntu0.14.04.1 . Oxide vulnerabilities threaten various Ubuntu versions. Critical patches for CVE-2023-12345 and others are essential for system security and integrity. OxideQt, Security Fix, Application Crashes, XSS Exploits. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 02, 2016 Critical Ubuntu
172

Ubuntu 15.10 and 14.04 LTS USN-2895-1 Moderate: Oxide Issues

Several security issues were fixed in Oxide.. =========================================================================Ubuntu Security Notice USN-2895-1 February 18, 2016 oxide-qt vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.10 - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Oxide. Software Description: - oxide-qt: Web browser engine library for Qt (QML plugin) Details: The DOM implementation in Chromium did not properly restrict frame-attach operations from occurring during or after frame-detach operations. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to bypass same-origin restrictions. (CVE-2016-1623) An integer underflow was discovered in Brotli. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking the program. (CVE-2016-1624) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: liboxideqtcore0 1.12.6-0ubuntu0.15.10.1 Ubuntu 14.04 LTS: liboxideqtcore0 1.12.6-0ubuntu0.14.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2895-1 CVE-2016-1623, CVE-2016-1624 Package Information: https://launchpad.net/ubuntu/+source/oxide-qt/1.12.6-0ubuntu0.15.10.1 https://launchpad.net/ubuntu/+source/oxide-qt/1.12.6-0ubuntu0.14.04.1 . Ubuntu 2895-2 addresses significant Metal flaws, encompassing essential safety issues and upgrade recommendations for users. Oxide Issues, Ubuntu Patch, Security Notice, Application Breach, Update Guidance. . LinuxSecurity.com Team

Calendar%202 Feb 18, 2016 Ubuntu
172

Ubuntu 14.04 & 15.04 LTS Oxide Advisory: Multiple Threats Detected

Several security issues were fixed in Oxide.. =========================================================================Ubuntu Security Notice USN-2677-1 August 04, 2015 oxide-qt vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.04 - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Oxide. Software Description: - oxide-qt: Web browser engine library for Qt (QML plugin) Details: An uninitialized value issue was discovered in ICU. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service. (CVE-2015-1270) A use-after-free was discovered in the GPU process implementation in Chromium. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking the program. (CVE-2015-1272) A use-after-free was discovered in the IndexedDB implementation in Chromium. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking the program. (CVE-2015-1276) A use-after-free was discovered in the accessibility implemetation in Chromium. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking the program. (CVE-2015-1277) A memory corruption issue was discovered in Skia. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash, or execute arbitrary code with the privileges ofthe sandboxed render process. (CVE-2015-1280) It was discovered that Blink did not properly determine the V8 context of a microtask in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to bypass Content Security Policy (CSP) restrictions. (CVE-2015-1281) Multiple integer overflows were discovered in Expat. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking the program. (CVE-2015-1283) It was discovered that Blink did not enforce a page's maximum number of frames in some circumstances, resulting in a use-after-free. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash, or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2015-1284) It was discovered that the XSS auditor in Blink did not properly choose a truncation point. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to obtain sensitive information. (CVE-2015-1285) An issue was discovered in the CSS implementation in Blink. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to bypass same-origin restrictions. (CVE-2015-1287) Multiple security issues were discovered in Chromium. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to read uninitialized memory, cause a denial of service via application crash or execute arbitrary code with the privileges of the user invoking the program. (CVE-2015-1289) A use-after-free was discovered in oxide::qt::URLRequestDelegatedJob in some circumstances. If a user were tricked in to opening a specially crafted website, anattacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking the program. (CVE-2015-1329) A crash was discovered in the regular expression implementation in V8 in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service. (CVE-2015-5605) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: liboxideqtcore0 1.8.4-0ubuntu0.15.04.1 Ubuntu 14.04 LTS: liboxideqtcore0 1.8.4-0ubuntu0.14.04.2 In general, a standard system update will make all the necessary changes. References: CVE-2015-1270, CVE-2015-1272, CVE-2015-1276, CVE-2015-1277, CVE-2015-1280, CVE-2015-1281, CVE-2015-1283, CVE-2015-1284, CVE-2015-1285, CVE-2015-1287, CVE-2015-1289, CVE-2015-1329, CVE-2015-5605, Package Information: https://launchpad.net/ubuntu/+source/oxide-qt/1.8.4-0ubuntu0.15.04.1 https://launchpad.net/ubuntu/+source/oxide-qt/1.8.4-0ubuntu0.14.04.2 . Several vulnerabilities addressed in Oxide impacting Ubuntu 15.04 and 14.04 LTS. Keep informed for improved protection.. Oxide Security, Ubuntu Updates, Web Browser Threats. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 04, 2015 Critical Ubuntu
172

Ubuntu 15.04 USN-2610-1 Critical: Oxide Security Issues Overview

Several security issues were fixed in Oxide.. =========================================================================Ubuntu Security Notice USN-2610-1 May 21, 2015 oxide-qt vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.04 - Ubuntu 14.10 - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Oxide. Software Description: - oxide-qt: Web browser engine library for Qt (QML plugin) Details: Several security issues were discovered in the DOM implementation in Blink. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to bypass Same Origin Policy restrictions. (CVE-2015-1253, CVE-2015-1254) A use-after-free was discovered in the WebAudio implementation in Chromium. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash, or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2015-1255) A use-after-free was discovered in the SVG implementation in Blink. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash, or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2015-1256) A security issue was discovered in the SVG implementation in Blink. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash. (CVE-2015-1257) An issue was discovered with the build of libvpx. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash, or execute arbitrary code with the privileges of the sandboxed renderprocess. (CVE-2015-1258) Multiple use-after-free issues were discovered in the WebRTC implementation in Chromium. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via renderer crash, or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2015-1260) An uninitialized value bug was discovered in the font shaping code in Blink. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash. (CVE-2015-1262) Multiple security issues were discovered in Chromium. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to read uninitialized memory, cause a denial of service via application crash or execute arbitrary code with the privileges of the user invoking the program. (CVE-2015-1265) Multiple security issues were discovered in V8. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to read uninitialized memory, cause a denial of service via renderer crash or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2015-3910) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: liboxideqtcore0 1.7.8-0ubuntu0.15.04.1 oxideqt-codecs 1.7.8-0ubuntu0.15.04.1 oxideqt-codecs-extra 1.7.8-0ubuntu0.15.04.1 Ubuntu 14.10: liboxideqtcore0 1.7.8-0ubuntu0.14.10.1 oxideqt-codecs 1.7.8-0ubuntu0.14.10.1 oxideqt-codecs-extra 1.7.8-0ubuntu0.14.10.1 Ubuntu 14.04 LTS: liboxideqtcore0 1.7.8-0ubuntu0.14.04.1 oxideqt-codecs 1.7.8-0ubuntu0.14.04.1 oxideqt-codecs-extra 1.7.8-0ubuntu0.14.04.1 In general, a standard system updatewill make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2610-1 CVE-2015-1253, CVE-2015-1254, CVE-2015-1255, CVE-2015-1256, CVE-2015-1257, CVE-2015-1258, CVE-2015-1260, CVE-2015-1262, CVE-2015-1265, CVE-2015-3910 Package Information: https://launchpad.net/ubuntu/+source/oxide-qt/1.7.8-0ubuntu0.15.04.1 https://launchpad.net/ubuntu/+source/oxide-qt/1.7.8-0ubuntu0.14.10.1 https://launchpad.net/ubuntu/+source/oxide-qt/1.7.8-0ubuntu0.14.04.1 . Several security flaws in Oxide have been reported and resolved in this Ubuntu security update, impacting various iterations of the operating system.. Oxide Issues, Ubuntu Fixes, Security Threats, Web Engine Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 21, 2015 Critical Ubuntu
172

Ubuntu 15.04: USN-2570-1 Critical: Oxide Security Issues and Fixes

Several security issues were fixed in Oxide.. =========================================================================Ubuntu Security Notice USN-2570-1 April 27, 2015 oxide-qt vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.04 - Ubuntu 14.10 - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Oxide. Software Description: - oxide-qt: Web browser engine library for Qt (QML plugin) Details: An issue was discovered in the HTML parser in Blink. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to bypass same-origin restrictions. (CVE-2015-1235) An issue was discovered in the Web Audio API implementation in Blink. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to bypass same-origin restrictions. (CVE-2015-1236) A use-after-free was discovered in Chromium. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash, or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2015-1237) An out-of-bounds write was discovered in Skia. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash or execute arbitrary code with the privileges of the user invoking the program. (CVE-2015-1238) An out-of-bounds read was discovered in the WebGL implementation. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash. (CVE-2015-1240) An issue was discovered with the interaction of page navigation and touch event handling. If a user were tricked in to opening a specially crafted website, an attackercould potentially exploit this to conduct "tap jacking" attacks. (CVE-2015-1241) A type confusion bug was discovered in V8. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash, or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2015-1242) It was discovered that websocket connections were not upgraded whenever a HSTS policy is active. A remote attacker could potentially exploit this to conduct a man in the middle (MITM) attack. (CVE-2015-1244) An out-of-bounds read was discovered in Blink. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash. (CVE-2015-1246) Multiple security issues were discovered in Chromium. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to read uninitialized memory, cause a denial of service via application crash or execute arbitrary code with the privileges of the user invoking the program. (CVE-2015-1249) A use-after-free was discovered in the file picker implementation. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash or execute arbitrary code with the privileges of the user invoking the program. (CVE-2015-1321) Multiple security issues were discovered in V8. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to read uninitialized memory, cause a denial of service via renderer crash or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2015-3333) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: liboxideqtcore0 1.6.5-0ubuntu0.15.04.1 oxideqt-codecs 1.6.5-0ubuntu0.15.04.1 oxideqt-codecs-extra 1.6.5-0ubuntu0.15.04.1 Ubuntu 14.10: liboxideqtcore0 1.6.5-0ubuntu0.14.10.1 oxideqt-codecs 1.6.5-0ubuntu0.14.10.1 oxideqt-codecs-extra 1.6.5-0ubuntu0.14.10.1 Ubuntu 14.04 LTS: liboxideqtcore0 1.6.5-0ubuntu0.14.04.1 oxideqt-codecs 1.6.5-0ubuntu0.14.04.1 oxideqt-codecs-extra 1.6.5-0ubuntu0.14.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2570-1 CVE-2015-1235, CVE-2015-1236, CVE-2015-1237, CVE-2015-1238, CVE-2015-1240, CVE-2015-1241, CVE-2015-1242, CVE-2015-1244, CVE-2015-1246, CVE-2015-1249, CVE-2015-1321, CVE-2015-3333 Package Information: https://launchpad.net/ubuntu/+source/oxide-qt/1.6.5-0ubuntu0.15.04.1 https://launchpad.net/ubuntu/+source/oxide-qt/1.6.5-0ubuntu0.14.10.1 https://launchpad.net/ubuntu/+source/oxide-qt/1.6.5-0ubuntu0.14.04.1 . Ubuntu Security Notice USN-2571-1 outlines various vulnerabilities in the Oxide framework and offers essential steps for implementing updates.. Oxide Security, Software Patch, Ubuntu Threat Update, Web Application Risks. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 27, 2015 Critical Ubuntu
172

Ubuntu 14.10 & 14.04 LTS USN-2410-1 Moderate: Oxide Buffer Overflow

Several security issues were fixed in Oxide.. =========================================================================Ubuntu Security Notice USN-2410-1 November 19, 2014 oxide-qt vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.10 - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Oxide. Software Description: - oxide-qt: Web browser engine library for Qt (QML plugin) Details: A buffer overflow was discovered in Skia. If a user were tricked in to opening a specially crafted website, an attacked could potentially exploit this to cause a denial of service via renderer crash or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2014-7904) Multiple use-after-frees were discovered in Blink. If a user were tricked in to opening a specially crafted website, an attacked could potentially exploit these to cause a denial of service via renderer crash or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2014-7907) An integer overflow was discovered in media. If a user were tricked in to opening a specially crafted website, an attacked could potentially exploit this to cause a denial of service via renderer crash or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2014-7908) An uninitialized memory read was discovered in Skia. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash. (CVE-2014-7909) Multiple security issues were discovered in Chromium. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to read uninitialized memory, cause a denial of service via application crash or execute arbitrary code with the privileges of the user invoking the program. (CVE-2014-7910) Updateinstructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: liboxideqtcore0 1.3.4-0ubuntu0.14.10.1 oxideqt-codecs 1.3.4-0ubuntu0.14.10.1 oxideqt-codecs-extra 1.3.4-0ubuntu0.14.10.1 Ubuntu 14.04 LTS: liboxideqtcore0 1.3.4-0ubuntu0.14.04.1 oxideqt-codecs 1.3.4-0ubuntu0.14.04.1 oxideqt-codecs-extra 1.3.4-0ubuntu0.14.04.1 In general, a standard system update will make all the necessary changes. References: CVE-2014-7904, CVE-2014-7907, CVE-2014-7908, CVE-2014-7909, CVE-2014-7910 Package Information: https://launchpad.net/ubuntu/+source/oxide-qt/1.3.4-0ubuntu0.14.10.1 https://launchpad.net/ubuntu/+source/oxide-qt/1.3.4-0ubuntu0.14.04.1 . =========================================================================Ubuntu Security Notice USN-. security, oxide, =======================================================. . LinuxSecurity.com Team

Calendar%202 Nov 19, 2014 Ubuntu
172

Ubuntu 14.04 LTS: USN-2326-1 Moderate: Oxide Use-After-Free Threat

Several security issues were fixed in Oxide.. =========================================================================Ubuntu Security Notice USN-2326-1 September 02, 2014 oxide-qt vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Oxide. Software Description: - oxide-qt: Web browser engine library for Qt (QML plugin) Details: A use-after-free was discovered in the SVG implementation in Blink. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash, or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2014-3168) A use-after-free was discovered in the DOM implementation in Blink. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash, or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2014-3169) A use-after-free was discovered in V8. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via renderer crash, or execute arbitrary code with the privileges of the sandboxed render process. (CVE-2014-3171) It was discovered that WebGL clear calls did not interact properly with the state of a draw buffer. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service. (CVE-2014-3173) A threading issue was discovered in the Web Audio API during attempts to update biquad filter coefficients. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service. (CVE-2014-3174) Multiple security issues werediscovered in Chromium. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to read uninitialized memory, cause a denial of service via application crash or execute arbitrary code with the privileges of the user invoking the program. (CVE-2014-3175) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: liboxideqtcore0 1.1.2-0ubuntu0.14.04.1 oxideqt-codecs 1.1.2-0ubuntu0.14.04.1 oxideqt-codecs-extra 1.1.2-0ubuntu0.14.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2326-1 CVE-2014-3168, CVE-2014-3169, CVE-2014-3171, CVE-2014-3173, CVE-2014-3174, CVE-2014-3175 Package Information: https://launchpad.net/ubuntu/+source/oxide-qt/1.1.2-0ubuntu0.14.04.1 . Addressed vulnerabilities in Oxide following USN-2326-1 impacting Ubuntu 14.04 LTS, which presented various exploitation paths.. Oxide vulnerabilities, Ubuntu 14.04 LTS, cybersecurity update, security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 02, 2014 Important Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200