CVE-2015-5200
published 2015-09-08CVE-2015-5200: The trace functionality in libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to write to arbitrary files via unspecified…
PriorityP422medium6.3CVSS 2.0
AVLACMAuNCNICAC
EPSS
0.36%
28.5th percentile
The trace functionality in libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to write to arbitrary files via unspecified vectors.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libvdpau | < libvdpau 1.1.1-1 (bookworm) | libvdpau 1.1.1-1 (bookworm) |
| libvdpau_project | libvdpau | <= 1.1.0 | — |
| libvdpau_project | libvdpau | >= 0 < 1.1.1-1 | 1.1.1-1 |
| libvdpau_project | libvdpau | >= 0 < 1.1.1-1 | 1.1.1-1 |
| libvdpau_project | libvdpau | >= 0 < 1.1.1-1 | 1.1.1-1 |
| libvdpau_project | libvdpau | >= 0 < 1.1.1-1 | 1.1.1-1 |
| saltstack | salt | >= 0 < 2015.8.13 | 2015.8.13 |
| saltstack | salt | >= 2016.11.0 < 2016.11.2 | 2016.11.2 |
| saltstack | salt | >= 2016.3.0 < 2016.3.5 | 2016.3.5 |
CVSS provenance
nvdv2.06.3MEDIUMAV:L/AC:M/Au:N/C:N/I:C/A:C
osv6.3MEDIUM
vendor_redhat8.8HIGH
vendor_debian6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
salt: Salt-api allows arbitrary command execution on a salt-master via Salt's ssh_client
vendor_redhat·2017-01-20·CVSS 8.8
CVE-2017-5200 [HIGH] salt: Salt-api allows arbitrary command execution on a salt-master via Salt's ssh_client
salt: Salt-api allows arbitrary command execution on a salt-master via Salt's ssh_client
Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-master via Salt's ssh_client.
Statement: This issue did not affect the versions of the salt as shipped with Red Hat Ceph Storage 1.3, Red Hat Ceph Storage 2, and Red Hat Storage Console 2 as salt-api and salt-ssh are not shipped with these products.
Mitigation: Disable salt-api for mitigation.
Package: salt (Red Hat Ceph Storage 1.3) - Not affected
Package: salt (Red Hat Ceph Storage 2) - Not affected
Package: salt (Red Hat Storage Console 2) - Not affected
Ubuntu
libvdpau vulnerabilities
vendor_ubuntu·2015-09-03
CVE-2015-5198 libvdpau vulnerabilities
Title: libvdpau vulnerabilities
Summary: libvdpau could be made to run programs as an administrator.
Florian Weimer discovered that libvdpau incorrectly handled certain
environment variables. A local attacker could possibly use this issue to
gain privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libvdpau vulnerability in trace functionality
vendor_redhat·2015-08-31·CVSS 6.3
CVE-2015-5200 [MEDIUM] libvdpau vulnerability in trace functionality
libvdpau vulnerability in trace functionality
The trace functionality in libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to write to arbitrary files via unspecified vectors.
Package: libvdpau (Red Hat Enterprise Linux 7) - Affected
Debian
CVE-2015-5200: libvdpau - The trace functionality in libvdpau before 1.1.1, when used in a setuid or setgi...
vendor_debian·2015·CVSS 6.3
CVE-2015-5200 [MEDIUM] CVE-2015-5200: libvdpau - The trace functionality in libvdpau before 1.1.1, when used in a setuid or setgi...
The trace functionality in libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to write to arbitrary files via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 1.1.1-1)
bullseye: resolved (fixed in 1.1.1-1)
forky: resolved (fixed in 1.1.1-1)
sid: resolved (fixed in 1.1.1-1)
trixie: resolved (fixed in 1.1.1-1)
GHSA
GHSA-3qwj-pv6x-95j3: The trace functionality in libvdpau before 1
ghsa_unreviewed·2022-05-17
CVE-2015-5200 [MEDIUM] GHSA-3qwj-pv6x-95j3: The trace functionality in libvdpau before 1
The trace functionality in libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to write to arbitrary files via unspecified vectors.
GHSA
SaltStack Salt arbitrary command execution in Salt-api via ssh_client
ghsa·2022-05-13
CVE-2017-5200 [HIGH] SaltStack Salt arbitrary command execution in Salt-api via ssh_client
SaltStack Salt arbitrary command execution in Salt-api via ssh_client
Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-master via Salt's ssh_client.
OSV
CVE-2015-5200: The trace functionality in libvdpau before 1
osv·2015-09-08·CVSS 6.3
CVE-2015-5200 [MEDIUM] CVE-2015-5200: The trace functionality in libvdpau before 1
The trace functionality in libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to write to arbitrary files via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-5200 salt: Salt-api allows arbitrary command execution on a salt-master via Salt's ssh_client
bugzilla·2017-02-01·CVSS 8.8
CVE-2017-5200 [HIGH] CVE-2017-5200 salt: Salt-api allows arbitrary command execution on a salt-master via Salt's ssh_client
CVE-2017-5200 salt: Salt-api allows arbitrary command execution on a salt-master via Salt's ssh_client
Users of Salt-API and salt-ssh could execute a command on the salt master via a hole when both systems were enabled.
References:
https://docs.saltstack.com/en/2016.3/topics/releases/2015.8.13.html
Discussion:
Created salt tracking bugs for this issue:
Affects: epel-all [bug 1418350]
---
Mitigation:
Disable salt-api for mitigation.
---
Statement:
This issue did not affect the versions of the salt as shipped with Red Hat Ceph Storage 1.3, Red Hat Ceph Storage 2, and Red Hat Storage Console 2 as salt-api and salt-ssh are not shipped with these products.
---
Upstream Fixes:
https://github.com/saltstack/salt/pull/38743
https://github.com/saltstack/salt/pull/38759
Bugzilla
CVE-2015-5198 CVE-2015-5199 CVE-2015-5200 libvdpau: various flaws [fedora-all]
bugzilla·2015-08-31·CVSS 7.2
CVE-2015-5198 [HIGH] CVE-2015-5198 CVE-2015-5199 CVE-2015-5200 libvdpau: various flaws [fedora-all]
CVE-2015-5198 CVE-2015-5199 CVE-2015-5200 libvdpau: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2015-5200 libvdpau vulnerability in trace functionality
bugzilla·2015-08-14·CVSS 6.3
CVE-2015-5200 [MEDIUM] CVE-2015-5200 libvdpau vulnerability in trace functionality
CVE-2015-5200 libvdpau vulnerability in trace functionality
It was discovered that the trace functionality of libvdpau can be used to overwrite arbitrary files if the process underwent a trust transition at startup. This may allow local attackers gain additional privileges.
Acknowledgements:
This issue was discovered by Florian Weimer of Red Hat Product Security.
Discussion:
External references:
http://lists.x.org/archives/xorg-announce/2015-August/002630.html
---
Created libvdpau tracking bugs for this issue:
Affects: fedora-all [bug 1258644]
---
libvdpau-1.1.1-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
---
Upstream patch:
http://cgit.freedesktop.org/~aplattner/libvdpau/commit/?id=d1f9c16b1
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170637.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165546.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/167469.htmlhttp://lists.opensuse.org/opensuse-updates/2015-09/msg00012.htmlhttp://lists.x.org/archives/xorg-announce/2015-August/002630.htmlhttp://www.debian.org/security/2015/dsa-3355http://www.securityfocus.com/bid/76636http://www.ubuntu.com/usn/USN-2729-1https://bugzilla.redhat.com/show_bug.cgi?id=1253827http://lists.fedoraproject.org/pipermail/package-announce/2015-November/170637.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/165546.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/167469.htmlhttp://lists.opensuse.org/opensuse-updates/2015-09/msg00012.htmlhttp://lists.x.org/archives/xorg-announce/2015-August/002630.htmlhttp://www.debian.org/security/2015/dsa-3355http://www.securityfocus.com/bid/76636http://www.ubuntu.com/usn/USN-2729-1https://bugzilla.redhat.com/show_bug.cgi?id=1253827
2015-09-08
Published