PT-2015-3092 · Joyent+1 · Libuv+1

Saghul

·

Published

2015-05-05

·

Updated

2023-02-12

·

CVE-2015-0278

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libuv versions prior to 0.10.34
Description The issue is related to libuv not properly dropping group privileges, which allows attackers to gain privileges via unspecified vectors. The vulnerability is associated with errors in updating group privileges. Exploitation of the vulnerability may allow a remote attacker to elevate their privileges.
Recommendations For versions prior to 0.10.34, update to version 0.10.34 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive resources to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1086
BDU:2016-00297
CVE-2015-0278
MGASA-2015-0186

Affected Products

Alt Linux
Libuv