MGASA-2015-0186

Source
https://advisories.mageia.org/MGASA-2015-0186.html
Import Source
https://advisories.mageia.org/MGASA-2015-0186.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0186
Upstream
  • CVE-2015-0278
Published
2015-05-05T13:36:50Z
Modified
2026-04-16T06:26:16.729887919Z
Summary
Updated nodejs packages fix security vulnerabilities
Details

Updated nodejs package fixes security vulnerability:

It was found that libuv does not call setgoups before calling setuid/setgid. This may potentially allow an attacker to gain elevated privileges (CVE-2015-0278).

The libuv library is bundled with nodejs, and a fixed version of libuv is included with nodejs as of version 0.10.37. The nodejs package has been updated to version 0.10.38 to fix this issue, as well as several other bugs.

References
Credits

Affected packages

Mageia:4 / nodejs

Package

Name
nodejs
Purl
pkg:rpm/mageia/nodejs?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.10.38-1.mga4

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2015-0186.json"