PT-2015-1991 · Nvidia+3 · Libvdpau+3

Florian Weimer

·

Publicado

2015-09-01

·

Atualizado

2016-12-22

·

CVE-2015-5200

CVSS v2.0

6.3

Média

VetorAV:L/AC:M/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions libvdpau versions prior to 1.1.1
Description The issue is related to the trace functionality in libvdpau, which can be exploited by local users to write to arbitrary files when used in a setuid or setgid application. The vulnerability is also associated with incorrect handling of an environment variable, allowing a local attacker to perform unauthorized file writes.
Recommendations For versions prior to 1.1.1, update to version 1.1.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the trace functionality in setuid or setgid applications until a patch is applied. Avoid using the library in applications where it may be exploited by local users.

Correção

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1741
BDU:2015-11337
CVE-2015-5200
DLA-306-1
DSA-3355-1
DSA-3355-2
MGASA-2015-0364
OPENSUSE-SU-2024:10224-1
SUSE-SU-2015:1892-1
SUSE-SU-2015:1925-1
USN-2729-1

Produtos afetados

Alt Linux
Suse
Ubuntu
Libvdpau