[ MDVSA-2015:228 ] nodejs

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

 _______________________________________________________________________

 Mandriva Linux Security Advisory                         MDVSA-2015:228
 http://www.mandriva.com/en/support/security/
 _______________________________________________________________________

 Package : nodejs
 Date    : May 6, 2015
 Affected: Business Server 2.0
 _______________________________________________________________________

 Problem Description:

 Updated nodejs package fixes security vulnerability:
 
 It was found that libuv does not call setgoups before calling
 setuid/setgid. This may potentially allow an attacker to gain elevated
 privileges (CVE-2015-0278).
 
 The libuv library is bundled with nodejs, and a fixed version of
 libuv is included with nodejs as of version 0.10.37.  The nodejs
 package has been updated to version 0.10.38 to fix this issue, as
 well as several other bugs.
 _______________________________________________________________________

 References:

 h

Leave a Reply