First published: Mon May 18 2015(Updated: )
libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Fedora | =21 | |
libuv | <=0.10.33 | |
Node.js | <0.10.37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0278 is considered a medium severity vulnerability due to its potential to allow privilege escalation.
To fix CVE-2015-0278, upgrade libuv to version 0.10.34 or later, or ensure you are using an updated version of affected software like Node.js.
CVE-2015-0278 affects libuv versions prior to 0.10.34, Node.js versions prior to 0.10.37, and Fedora 21.
CVE-2015-0278 is a privilege escalation vulnerability that allows attackers to gain elevated permissions.
The exploitability of CVE-2015-0278 depends on the attack vectors which are context-dependent, implying some scenarios may allow remote exploitation.