CVE-2015-7810: Medium severity Videolan Libbluray vulnerability
libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-7810?
CVE-2015-7810 is a vulnerability in the libbluray MountManager class that allows a time-of-check time-of-use (TOCTOU) race condition when expanding JAR files.
How severe is CVE-2015-7810?
CVE-2015-7810 has a severity score of 4.7, which is considered medium.
What is the affected software for CVE-2015-7810?
The affected software for CVE-2015-7810 includes libbluray package versions 1:1.1.0-1, 1:1.1.0-1+deb10u1, 1:1.2.1-4+deb11u2, and 1:1.3.4-1 on Debian systems. It also includes Videolan Libbluray versions up to 0.8.0, Redhat Enterprise Linux version 7.0, Fedora versions 17 and 18, and Debian Linux versions 8.0, 9.0, and 10.0.
How do I fix CVE-2015-7810?
To fix CVE-2015-7810, update the libbluray package to a patched version provided by the respective vendor or distribution.
Where can I find more information about CVE-2015-7810?
You can find more information about CVE-2015-7810 at the following references: [1](http://www.openwall.com/lists/oss-security/2015/10/12/7), [2](http://www.securityfocus.com/bid/72769), [3](https://access.redhat.com/security/cve/cve-2015-7810).