PT-2015-1991 · Nvidia+3 · Libvdpau+3
Florian Weimer
·
Publicado
2015-09-01
·
Atualizado
2016-12-22
·
CVE-2015-5200
CVSS v2.0
6.3
Média
| Vetor | AV:L/AC:M/Au:N/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
libvdpau versions prior to 1.1.1
Description
The issue is related to the trace functionality in libvdpau, which can be exploited by local users to write to arbitrary files when used in a setuid or setgid application. The vulnerability is also associated with incorrect handling of an environment variable, allowing a local attacker to perform unauthorized file writes.
Recommendations
For versions prior to 1.1.1, update to version 1.1.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the trace functionality in setuid or setgid applications until a patch is applied. Avoid using the library in applications where it may be exploited by local users.
Correção
Integer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Suse
Ubuntu
Libvdpau