Zum Hauptinhalt springen
Windows Tipps & SecurityBest AI browsers for Windows 11(19.09.2026 um 00:38 Uhr)
Sichere ProgrammierungAgent stdout Is Not Your Test Plan(19.09.2026 um 02:03 Uhr)
Sichere ProgrammierungThumbs Up with a Twist - Correction and Smoothing of Grip(19.09.2026 um 02:04 Uhr)
Sichere ProgrammierungAuth Provider Event History vs. Your Audit Log: SOC 2 Evidence(19.09.2026 um 02:04 Uhr)
Sichere ProgrammierungThe Deadline Used time.time(). Then the Laptop Slept.(19.09.2026 um 02:04 Uhr)
Windows Tipps & SecurityBest AI browsers for Windows 11(19.09.2026 um 00:38 Uhr)
Sichere ProgrammierungAgent stdout Is Not Your Test Plan(19.09.2026 um 02:03 Uhr)
Sichere ProgrammierungThumbs Up with a Twist - Correction and Smoothing of Grip(19.09.2026 um 02:04 Uhr)
Sichere ProgrammierungAuth Provider Event History vs. Your Audit Log: SOC 2 Evidence(19.09.2026 um 02:04 Uhr)
Sichere ProgrammierungThe Deadline Used time.time(). Then the Laptop Slept.(19.09.2026 um 02:04 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

USN-2877-1: Oxide vulnerabilities

Ubuntu Security Notice USN-2877-1

27th January, 2016

oxide-qt vulnerabilities

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 15.10
  • Ubuntu 15.04
  • Ubuntu 14.04 LTS

Summary

Several security issues were fixed in Oxide.

Software description

  • oxide-qt - Web browser engine library for Qt (QML plugin)

Details

A bad cast was discovered in V8. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
cause a denial of service via renderer crash or execute arbitrary code
with the privileges of the sandboxed render process. (CVE-2016-1612)

An issue was discovered when initializing the UnacceleratedImageBufferSurface
class in Blink. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to obtain sensitive
information. (CVE-2016-1614)

An issue was discovered with the CSP implementation in Blink. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to determine whether specific HSTS sites had been
visited by reading a CSP report. (CVE-2016-1617)

An issue was discovered with random number generator in Blink. An attacker
could potentially exploit this to defeat cryptographic protection
mechanisms. (CVE-2016-1618)

Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial
of service via application crash or execute arbitrary code with the
privileges of the user invoking the program. (CVE-2016-1620)

Multiple security issues were discovered in V8. If a user were tricked
in to opening a specially crafted website, an attacker could potentially
exploit these to read uninitialized memory, cause a denial of service via
renderer crash or execute arbitrary code with the privileges of the
sandboxed render process. (CVE-2016-2051)

Multiple security issues were discovered in Harfbuzz. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via renderer
crash or execute arbitrary code with the privileges of the sandboxed
render process. (CVE-2016-2052)

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 15.10:
liboxideqtcore0 1.12.5-0ubuntu0.15.10.1
Ubuntu 15.04:
liboxideqtcore0 1.12.5-0ubuntu0.15.04.1
Ubuntu 14.04 LTS:
liboxideqtcore0 1.12.5-0ubuntu0.14.04.1

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References

CVE-2016-1612, CVE-2016-1614, CVE-2016-1617, CVE-2016-1618, CVE-2016-1620, CVE-2016-2051, CVE-2016-2052

Ähnliche Beiträge
🔍 Verwandte News

Ähnliche Beiträge zu USN-2877-1: Oxide vulnerabilities

Thematisch verwandte Begriffe: USN28771, Oxide, vulnerabilities · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-61591 | djust provides Phoenix LiveView-style reactive server-side rendering for…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Rechts: Artikel Ziehen Links: RSS
Hoch: nächster Artikel Runter: zurück / schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Rechts: Original Links: RSS-Ansicht
↗ Original-Quelle
Social Reaktionen Stimme abgeben (+5 Karma)
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick