Mageia alert MGASA-2015-0364 (libvdpau)
| From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2015-0364: Updated libvdpau packages fix security vulnerabilities | |
| Date: | Sun, 13 Sep 2015 23:59:03 +0200 | |
| Message-ID: | <20150913215903.1782E59402@valstar.mageia.org> |
MGASA-2015-0364 - Updated libvdpau packages fix security vulnerabilities Publication date: 13 Sep 2015 URL: http://advisories.mageia.org/MGASA-2015-0364.html Type: security Affected Mageia releases: 4, 5 CVE: CVE-2015-5198, CVE-2015-5199, CVE-2015-5200 Description: Updated libvdpau packages fix security vulnerabilities: libvdpau versions 1.1 and earlier, when used in setuid or setgid applications, contain vulnerabilities related to environment variable handling that could allow an attacker to execute arbitrary code or overwrite arbitrary files (CVE-2015-5198, CVE-2015-5199, and CVE-2015-5200). References: - https://bugs.mageia.org/show_bug.cgi?id=16687 - http://lists.x.org/archives/xorg-announce/2015-August/002... - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5198 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5199 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5200 SRPMS: - 4/core/libvdpau-1.1.1-1.mga4 - 5/core/libvdpau-1.1.1-1.mga5
