|
|
Log in / Subscribe / Register

libvdpau: multiple vulnerabilities

Package(s):libvdpau CVE #(s):CVE-2015-5198 CVE-2015-5199 CVE-2015-5200
Created:September 4, 2015 Updated:November 3, 2015
Description:

From the CVE entries:

It was discovered that libvdpau incorrectly checks if the process underwent a security transition at startup, related to processing of the VDPAU_DRIVER_PATH environment variable. This may allow local attackers gain additional privileges. (CVE-2015-5198)

It was discovered that libvdpau does not guard against directory traversal while processing the VDPAU_DRIVER environment variable. This may allow local attackers gain additional privileges. (CVE-2015-5199)

It was discovered that the trace functionality of libvdpau can be used to overwrite arbitrary files if the process underwent a trust transition at startup. This may allow local attackers gain additional privileges. CVE-2015-5200)

Alerts:
Debian DSA-3355-2 libvdpau 2015-11-02
Fedora FEDORA-2015-3ca3f2138b libvdpau 2015-11-01
Fedora FEDORA-2015-14851 libvdpau 2015-09-24
openSUSE openSUSE-SU-2015:1537-1 libvdpau 2015-09-11
Arch Linux ASA-201509-5 libvdpau lib32-libvdpau 2015-09-13
Debian DSA-3355-1 libvdpau 2015-09-10
Mageia MGASA-2015-0364 libvdpau 2015-09-13
Debian-LTS DLA-306-1 libvdpau 2015-09-10
Ubuntu USN-2729-1 libvdpau 2015-09-03

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds