Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2016-1586

Published: 2 November 2016

A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3.

Priority

Medium

CVSS 3 base score: 7.5

Status

Package Release Status
oxide-qt
Launchpad, Ubuntu, Debian
precise Does not exist

trusty Does not exist
(trusty was released [1.18.3-0ubuntu0.14.04.1])
upstream
Released (1.18.2)
xenial
Released (1.18.3-0ubuntu0.16.04.1)
yakkety
Released (1.18.3-0ubuntu0.16.10.1)
Patches:
upstream: https://git.launchpad.net/oxide/commit/?id=29014da83e5fc358d6bff0f574e9ed45e61a35ac