Ubuntu Security Notice USN-2895-1

Discussion in 'News Aggregator' started by Packet Storm, 19 Feb 2016.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 2895-1 - The DOM implementation in Chromium did not properly restrict frame-attach operations from occurring during or after frame-detach operations. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to bypass same-origin restrictions. An integer underflow was discovered in Brotli. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking the program. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...