cbcvebase.
CVE-2015-5200
published 2015-09-08

CVE-2015-5200: The trace functionality in libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to write to arbitrary files via unspecified…

PriorityP422medium6.3CVSS 2.0
AVLACMAuNCNICAC
EPSS
0.36%
28.5th percentile
The trace functionality in libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to write to arbitrary files via unspecified vectors.

Affected

12 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianlibvdpau< libvdpau 1.1.1-1 (bookworm)libvdpau 1.1.1-1 (bookworm)
libvdpau_projectlibvdpau<= 1.1.0
libvdpau_projectlibvdpau>= 0 < 1.1.1-11.1.1-1
libvdpau_projectlibvdpau>= 0 < 1.1.1-11.1.1-1
libvdpau_projectlibvdpau>= 0 < 1.1.1-11.1.1-1
libvdpau_projectlibvdpau>= 0 < 1.1.1-11.1.1-1
saltstacksalt>= 0 < 2015.8.132015.8.13
saltstacksalt>= 2016.11.0 < 2016.11.22016.11.2
saltstacksalt>= 2016.3.0 < 2016.3.52016.3.5

CVSS provenance

nvdv2.06.3MEDIUMAV:L/AC:M/Au:N/C:N/I:C/A:C
osv6.3MEDIUM
vendor_redhat8.8HIGH
vendor_debian6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.