CVE-2015-0278: Critical severity red hat fedora vulnerability
libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-0278?
CVE-2015-0278 is considered a medium severity vulnerability due to its potential to allow privilege escalation.
How do I fix CVE-2015-0278?
To fix CVE-2015-0278, upgrade libuv to version 0.10.34 or later, or ensure you are using an updated version of affected software like Node.js.
Which software is affected by CVE-2015-0278?
CVE-2015-0278 affects libuv versions prior to 0.10.34, Node.js versions prior to 0.10.37, and Fedora 21.
What type of vulnerability is CVE-2015-0278?
CVE-2015-0278 is a privilege escalation vulnerability that allows attackers to gain elevated permissions.
Can CVE-2015-0278 be exploited remotely?
The exploitability of CVE-2015-0278 depends on the attack vectors which are context-dependent, implying some scenarios may allow remote exploitation.