Vulnerability Description
libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fedoraproject | Fedora | 21 |
| Libuv Project | Libuv | <= 0.10.33 |
| Nodejs | Node.Js | < 0.10.37 |
Related Weaknesses (CWE)
References
- http://advisories.mageia.org/MGASA-2015-0186.htmlThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:228Third Party Advisory
- https://github.com/libuv/libuv/commit/66ab38918c911bcff025562cf06237d7fedaba0cPatchThird Party Advisory
- https://github.com/libuv/libuv/pull/215Third Party Advisory
- https://groups.google.com/forum/#%21msg/libuv/0JZxwLMtsMI/jraczskYWWQJ
- https://lists.fedoraproject.org/pipermail/package-announce/2015-February/150526.Third Party Advisory
- https://security.gentoo.org/glsa/201611-10Third Party Advisory
- http://advisories.mageia.org/MGASA-2015-0186.htmlThird Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:228Third Party Advisory
- https://github.com/libuv/libuv/commit/66ab38918c911bcff025562cf06237d7fedaba0cPatchThird Party Advisory
- https://github.com/libuv/libuv/pull/215Third Party Advisory
- https://groups.google.com/forum/#%21msg/libuv/0JZxwLMtsMI/jraczskYWWQJ
- https://lists.fedoraproject.org/pipermail/package-announce/2015-February/150526.Third Party Advisory
- https://security.gentoo.org/glsa/201611-10Third Party Advisory
FAQ
What is CVE-2015-0278?
CVE-2015-0278 is a vulnerability with a CVSS score of 10.0 (HIGH). libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.
How severe is CVE-2015-0278?
CVE-2015-0278 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-0278?
Check the references section above for vendor advisories and patch information. Affected products include: Fedoraproject Fedora, Libuv Project Libuv, Nodejs Node.Js.