USN-2652-1
Dashboard / Vulnerabilities / USN-2652-1
USN-2652-1
Summary: oxide-qt vulnerabilities
Details: It was discovered that Chromium did not properly consider the scheme when determining whether a URL is associated with a WebUI SiteInstance. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to bypass security restrictions. (CVE-2015-1266) It was discovered that Blink did not properly restrict the creation context during creation of a DOM wrapper. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to bypass same-origin restrictions. (CVE-2015-1267, CVE-2015-1268) It was discovered that Chromium did not properly canonicalize DNS hostnames before comparing to HSTS or HPKP preload entries. An attacker could potentially exploit this to bypass intended access restrictions. (CVE-2015-1269)
References: https://ubuntu.com/security/notices/USN-2652-1, https://ubuntu.com/security/CVE-2015-1266, https://ubuntu.com/security/CVE-2015-1267, https://ubuntu.com/security/CVE-2015-1268, https://ubuntu.com/security/CVE-2015-1269
Affected packages
Package
Name: oxide-qt
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
