PT-2015-5206 · Canonical · Oxide+1

Chris Coulson

+1

·

Publicado

2015-04-07

·

Atualizado

2015-09-29

·

CVE-2015-1317

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oxide versions prior to 1.5.6 Oxide versions 1.6.x prior to 1.6.1
Description The issue is related to a use-after-free condition that can be triggered by remote attackers, potentially leading to a denial of service (crash) or the execution of arbitrary code. This is achieved by deleting all WebContents while a RenderProcessHost instance still exists.
Recommendations For Oxide versions prior to 1.5.6, update to version 1.5.6 or later. For Oxide versions 1.6.x prior to 1.6.1, update to version 1.6.1 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2015-1317
USN-2556-1

Produtos afetados

Oxide
Ubuntu