PT-2015-1991 · Nvidia+3 · Libvdpau+3

Florian Weimer

·

Published

2015-09-01

·

Updated

2016-12-22

·

CVE-2015-5200

CVSS v2.0

6.3

Medium

VectorAV:L/AC:M/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions libvdpau versions prior to 1.1.1
Description The issue is related to the trace functionality in libvdpau, which can be exploited by local users to write to arbitrary files when used in a setuid or setgid application. The vulnerability is also associated with incorrect handling of an environment variable, allowing a local attacker to perform unauthorized file writes.
Recommendations For versions prior to 1.1.1, update to version 1.1.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the trace functionality in setuid or setgid applications until a patch is applied. Avoid using the library in applications where it may be exploited by local users.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1741
BDU:2015-11337
CVE-2015-5200
DLA-306-1
DSA-3355-1
DSA-3355-2
MGASA-2015-0364
OPENSUSE-SU-2024:10224-1
SUSE-SU-2015:1892-1
SUSE-SU-2015:1925-1
USN-2729-1

Affected Products

Alt Linux
Suse
Ubuntu
Libvdpau