Mandriva Linux Security Advisory 2015-228

Discussion in 'News Aggregator' started by Packet Storm, 6 May 2015.

  1. Packet Storm

    Packet Storm Guest

    Mandriva Linux Security Advisory 2015-228 - It was found that libuv does not call setgoups before calling setuid/setgid. This may potentially allow an attacker to gain elevated privileges. The libuv library is bundled with nodejs, and a fixed version of libuv is included with nodejs as of version 0.10.37. The nodejs package has been updated to version 0.10.38 to fix this issue, as well as several other bugs.

    Continue reading...
     

Share This Page

Loading...