|
|
Subscribe / Log in / New account

oxide-qt: code execution

Package(s):oxide-qt CVE #(s):CVE-2015-1317
Created:April 7, 2015 Updated:April 8, 2015
Description: From the Ubuntu advisory:

It was discovered that Oxide did not correctly manage the lifetime of BrowserContext, resulting in a potential use-after-free in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash or execute arbitrary code with the privileges of the user invoking the program.

Alerts:
Ubuntu USN-2556-1 oxide-qt 2015-04-07

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds