CVE-2015-1321: Use After Free
Published Apr 29, 2015
·Updated
Use-after-free vulnerability in the file picker implementation in Oxide before 1.6.5 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted webpage.
Affected Software
4 affected components
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=14.10
Canonical Ubuntu Linux=15.1
Oxide Project Oxide<=1.6.4
Event History
Apr 29, 2015
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1321?
CVE-2015-1321 has a high severity rating due to its potential to cause a denial of service or execute arbitrary code.
2
How do I fix CVE-2015-1321?
To fix CVE-2015-1321, upgrade to Oxide version 1.6.5 or later.
3
What software is affected by CVE-2015-1321?
CVE-2015-1321 affects Oxide versions up to and including 1.6.4 and certain Ubuntu Linux versions including 14.04, 14.10, and 15.1.
4
What type of vulnerability is CVE-2015-1321?
CVE-2015-1321 is classified as a use-after-free vulnerability.
5
Can CVE-2015-1321 be exploited remotely?
Yes, CVE-2015-1321 can be exploited remotely through a crafted webpage.