libvdpau: multiple vulnerabilities
| Package(s): | libvdpau | CVE #(s): | CVE-2015-5198 CVE-2015-5199 CVE-2015-5200 | ||||||||||||||||||||||||||||||||||||
| Created: | September 4, 2015 | Updated: | November 3, 2015 | ||||||||||||||||||||||||||||||||||||
| Description: | From the CVE entries: It was discovered that libvdpau incorrectly checks if the process underwent a security transition at startup, related to processing of the VDPAU_DRIVER_PATH environment variable. This may allow local attackers gain additional privileges. (CVE-2015-5198) It was discovered that libvdpau does not guard against directory traversal while processing the VDPAU_DRIVER environment variable. This may allow local attackers gain additional privileges. (CVE-2015-5199) It was discovered that the trace functionality of libvdpau can be used to overwrite arbitrary files if the process underwent a trust transition at startup. This may allow local attackers gain additional privileges. CVE-2015-5200) | ||||||||||||||||||||||||||||||||||||||
| Alerts: |
| ||||||||||||||||||||||||||||||||||||||
