USN-2895-1
Dashboard / Vulnerabilities / USN-2895-1
USN-2895-1
Summary: oxide-qt vulnerabilities
Details: The DOM implementation in Chromium did not properly restrict frame-attach operations from occurring during or after frame-detach operations. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to bypass same-origin restrictions. (CVE-2016-1623) An integer underflow was discovered in Brotli. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking the program. (CVE-2016-1624)
References: https://ubuntu.com/security/notices/USN-2895-1, https://ubuntu.com/security/CVE-2016-1623, https://ubuntu.com/security/CVE-2016-1624
Affected packages
Package
Name: oxide-qt
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
