Input validation error - CVE-2015-5200
Published: September 8, 2015 / Updated: August 4, 2020
Vulnerability identifier: #VU33816
CSH Severity: High
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-5200
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to #BASIC_IMPACT#.
The trace functionality in libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to write to arbitrary files via unspecified vectors.
Affected software
libvdpau (Alpine package)
ruby (Alpine package)
libvdpau
Fedora
ruby (Alpine package)
libvdpau
Fedora
How to mitigate CVE-2015-5200
Install update from vendor's website.
libvdpau (Alpine package) - addressed in versions 0.7-r2, 0.8-r1, 1.1.1-r0
ruby (Alpine package) - update to 2.2.3-r0
libvdpau - addressed in versions 1.1.1-1.fc21, 1.1.1-1.fc22, 1.1.1-1.fc23, 1.1.1-2.fc21
ruby (Alpine package) - update to 2.2.3-r0
libvdpau - addressed in versions 1.1.1-1.fc21, 1.1.1-1.fc22, 1.1.1-1.fc23, 1.1.1-2.fc21
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170637.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165546.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167469.html
- http://lists.opensuse.org/opensuse-updates/2015-09/msg00012.html
- http://lists.x.org/archives/xorg-announce/2015-August/002630.html
- http://www.debian.org/security/2015/dsa-3355
- http://www.securityfocus.com/bid/76636
- http://www.ubuntu.com/usn/USN-2729-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1253827