PT-2015-1991 · Nvidia+3 · Libvdpau+3
Florian Weimer
·
Published
2015-09-01
·
Updated
2016-12-22
·
CVE-2015-5200
CVSS v2.0
6.3
Medium
| Vector | AV:L/AC:M/Au:N/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
libvdpau versions prior to 1.1.1
Description
The issue is related to the trace functionality in libvdpau, which can be exploited by local users to write to arbitrary files when used in a setuid or setgid application. The vulnerability is also associated with incorrect handling of an environment variable, allowing a local attacker to perform unauthorized file writes.
Recommendations
For versions prior to 1.1.1, update to version 1.1.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the trace functionality in setuid or setgid applications until a patch is applied. Avoid using the library in applications where it may be exploited by local users.
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Suse
Ubuntu
Libvdpau