libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.
2015-05-18T15:59:02.713
2025-04-12T10:46:40.837
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | fedoraproject | fedora | 21 | Yes |
Application | libuv_project | libuv | ≤ 0.10.33 | Yes |
Application | nodejs | node.js | < 0.10.37 | Yes |