Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The previous update for libvdpau, DSA-3355-1, introduced a regression in the stable distribution (jessie) causing a segmentation fault when the DRI_PRIME environment variable is set. For reference, the original advisory text follows. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3355-2
libvdpau-1.1.1-2.fc21 - Backport current patches - Switch to new upstream git repository on freedesktop.org ---- Update to 1.1.1 Security fix for CVE-2015-5198, CVE-2015-5199, CVE-2015-5200. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-3ca3f2138b 2015-11-01 18:13:40.462804 -------------------------------------------------------------------------------- Name : libvdpau Product : Fedora 21 Version : 1.1.1 Release : 2.fc21 URL : Summary : Wrapper library for the Video Decode and Presentation API Description : VDPAU is the Video Decode and Presentation API for UNIX. It provides an interface to video decode acceleration and presentation hardware present in modern GPUs. -------------------------------------------------------------------------------- Update Information: libvdpau-1.1.1-2.fc21 - Backport current patches - Switch to new upstream git repository on freedesktop.org ---- Update to 1.1.1 Security fix for CVE-2015-5198, CVE-2015-5199, CVE-2015-5200 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1253827 - CVE-2015-5200 libvdpau vulnerability in trace functionality https://bugzilla.redhat.com/show_bug.cgi?id=1253827 [ 2 ] Bug #1253826 - CVE-2015-5199 libvdpau directory traversal in dlopen https://bugzilla.redhat.com/show_bug.cgi?id=1253826 [ 3 ] Bug #1253824 - CVE-2015-5198 libvdpau incorrect check for security transition https://bugzilla.redhat.com/show_bug.cgi?id=1253824 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libvdpau' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Update to 1.1.1 Security fix for CVE-2015-5198, CVE-2015-5199, CVE-2015-5200. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-14851 2015-09-24 05:07:02.610836 -------------------------------------------------------------------------------- Name : libvdpau Product : Fedora 22 Version : 1.1.1 Release : 1.fc22 URL : Summary : Wrapper library for the Video Decode and Presentation API Description : VDPAU is the Video Decode and Presentation API for UNIX. It provides an interface to video decode acceleration and presentation hardware present in modern GPUs. -------------------------------------------------------------------------------- Update Information: Update to 1.1.1 Security fix for CVE-2015-5198, CVE-2015-5199, CVE-2015-5200 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1253827 - CVE-2015-5200 libvdpau vulnerability in trace functionality https://bugzilla.redhat.com/show_bug.cgi?id=1253827 [ 2 ] Bug #1253826 - CVE-2015-5199 libvdpau directory traversal in dlopen https://bugzilla.redhat.com/show_bug.cgi?id=1253826 [ 3 ] Bug #1253824 - CVE-2015-5198 libvdpau incorrect check for security transition https://bugzilla.redhat.com/show_bug.cgi?id=1253824 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libvdpau' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailinglist
The packages libvdpau and lib32-libvdpau before version 1.1.1-1 are vulnerable to multiple issues. . Arch Linux Security Advisory ASA-201509-5 ======================================== Severity: Medium Date : 2015-09-12 CVE-ID : CVE-2015-5198 CVE-2015-5199 CVE-2015-5200 Package : libvdpau lib32-libvdpau Type : multiple issues Remote : no Link : https://wiki.archlinux.org/title/CVE Summary ====== The packages libvdpau and lib32-libvdpau before version 1.1.1-1 are vulnerable to multiple issues. Resolution ========= Upgrade to 1.1.1-1 # pacman -Syu "libvdpau> =1.1.1-1" if you need lib32-libvdpau: # pacman -Syu "libvdpau> =1.1.1-1" "lib32-libvdpau> =1.1.1-1" Workaround ========= None. Description ========== - CVE-2015-5198 (Local Privilege Escalation) When used in a setuid or setgid application, libvdpau/lib32-libvdpau allows local users to gain privileges via unspecified vectors, related to the VDPAU_DRIVER_PATH environment variable. - CVE-2015-5199 (Directory Traversal) Directory traversal vulnerability in dlopen in libvdpau/lib32/libvdpau allows local users to gain privileges via the VDPAU_DRIVER environment variable. - CVE-2015-5200 (Directory Traversal) The trace functionality in libvdpau/lib32-libvdpau, when used in a setuid or setgid application, allows local users to write to arbitrary files via unspecified vectors. Impact ===== An attacker can gain root-access or write to arbitrary files without permission. References ========= https://lists.x.org/archives/xorg-announce/2015-August/002630.html https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-5198 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-5199 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-5200 . Arch Linux Security Advisory ASA-201509-5 ======================================== Severity: Medium . packages, libvdpau, lib32-libvdpau, version, vulnerable. . Severity: Medium. LinuxSecurity.com Team
Florian Weimer of Red Hat Product Security discovered that libvdpau, the VDPAU wrapper library, did not properly validate environment variables, allowing local attackers to gain additional privileges. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3355-1
Update to 1.1.1 Security fix for CVE-2015-5198, CVE-2015-5199, CVE-2015-5200. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-14850 2015-09-04 19:45:14.258973 -------------------------------------------------------------------------------- Name : libvdpau Product : Fedora 23 Version : 1.1.1 Release : 1.fc23 URL : https://freedesktop.org/wiki/Software/VDPAU/?__goaway_challenge=meta-refresh&__goaway_id=5782895683af732fa072cd835f7d8fc3 Summary : Wrapper library for the Video Decode and Presentation API Description : VDPAU is the Video Decode and Presentation API for UNIX. It provides an interface to video decode acceleration and presentation hardware present in modern GPUs. -------------------------------------------------------------------------------- Update Information: Update to 1.1.1 Security fix for CVE-2015-5198, CVE-2015-5199, CVE-2015-5200 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1253827 - CVE-2015-5200 libvdpau vulnerability in trace functionality https://bugzilla.redhat.com/show_bug.cgi?id=1253827 [ 2 ] Bug #1253826 - CVE-2015-5199 libvdpau directory traversal in dlopen https://bugzilla.redhat.com/show_bug.cgi?id=1253826 [ 3 ] Bug #1253824 - CVE-2015-5198 libvdpau incorrect check for security transition https://bugzilla.redhat.com/show_bug.cgi?id=1253824 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libvdpau' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
libvdpau could be made to run programs as an administrator.. =========================================================================Ubuntu Security Notice USN-2729-1 September 03, 2015 libvdpau vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.04 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: libvdpau could be made to run programs as an administrator. Software Description: - libvdpau: Video Decode and Presentation API for Unix Details: Florian Weimer discovered that libvdpau incorrectly handled certain environment variables. A local attacker could possibly use this issue to gain privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: libvdpau1 0.9-1ubuntu0.1 Ubuntu 14.04 LTS: libvdpau1 0.7-1ubuntu0.1 Ubuntu 12.04 LTS: libvdpau1 0.4.1-3ubuntu1.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2729-1 CVE-2015-5198, CVE-2015-5199, CVE-2015-5200 Package Information: https://launchpad.net/ubuntu/+source/libvdpau/0.9-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libvdpau/0.7-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libvdpau/0.4.1-3ubuntu1.2 . =========================================================================Ubuntu Security Notice USN-. libvdpau, programs, administrator, ========================================. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.