CVE-2015-0278
published 2015-05-18CVE-2015-0278: libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.
PriorityP344critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.24%
86.9th percentile
libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| libuv_project | libuv | <= 0.10.33 | — |
| nodejs | node.js | < 0.10.37 | 0.10.37 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libuv: incorrect revocation order while relinquishing privileges
vendor_redhat·2014-02-10·CVSS 10.0
CVE-2015-0278 [CRITICAL] libuv: incorrect revocation order while relinquishing privileges
libuv: incorrect revocation order while relinquishing privileges
libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.
Package: nodejs010-libuv (Red Hat Software Collections) - Will not fix
GHSA
GHSA-hmvq-6hjm-q8hj: libuv before 0
ghsa_unreviewed·2022-05-14
CVE-2015-0278 [HIGH] CWE-273 GHSA-hmvq-6hjm-q8hj: libuv before 0
libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2015-0186.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2015:228https://github.com/libuv/libuv/commit/66ab38918c911bcff025562cf06237d7fedaba0chttps://github.com/libuv/libuv/pull/215https://groups.google.com/forum/#%21msg/libuv/0JZxwLMtsMI/jraczskYWWQJhttps://lists.fedoraproject.org/pipermail/package-announce/2015-February/150526.htmlhttps://security.gentoo.org/glsa/201611-10http://advisories.mageia.org/MGASA-2015-0186.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2015:228https://github.com/libuv/libuv/commit/66ab38918c911bcff025562cf06237d7fedaba0chttps://github.com/libuv/libuv/pull/215https://groups.google.com/forum/#%21msg/libuv/0JZxwLMtsMI/jraczskYWWQJhttps://lists.fedoraproject.org/pipermail/package-announce/2015-February/150526.htmlhttps://security.gentoo.org/glsa/201611-10
2015-05-18
Published