CVE-2015-2675

Publication date 18 August 2017

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

7.5 · High

Score breakdown

Description

The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows remote attackers to cause a denial of service (application crash) via running the EnsureCredentials method from the org.gnome.OnlineAccounts.Account interface on an object representing a Flickr account.

Read the notes from the security team

Status

Package Ubuntu Release Status
librest 14.10 utopic
Not affected
14.04 LTS trusty Not in release
12.04 LTS precise
Not affected
10.04 LTS lucid
Not affected

Notes


mdeslaur

introduced by 55f8e962, which is only in 0.7.92

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
librest

Severity score breakdown

CVSS version: CVSS v3.0

Base score 7.5 · High

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H


Access our resources on patching vulnerabilities