10
CVSSv2

CVE-2015-0278

Published: 18/05/2015 Updated: 12/02/2023
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

libuv prior to 0.10.34 does not properly drop group privileges, which allows context-dependent malicious users to gain privileges via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

fedoraproject fedora 21

libuv project libuv

nodejs node.js

Vendor Advisories

Debian Bug report logs - #779173 libuv: CVE-2015-0278: incorrect revocation order while relinquishing privileges Package: src:libuv; Maintainer for src:libuv is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 25 Feb 2015 06: ...
libuv before 01034 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors ...