DSA-3355-2 libvdpau -- libvdpauID: oval:org.secpod.oval:def:602267 | Date: (C)2015-11-06 (M)2021-09-13 |
Class: PATCH | Family: unix |
The previous update for libvdpau, DSA-3355-1, introduced a regression in the stable distribution causing a segmentation fault when the DRI_PRIME environment variable is set. For reference, the original advisory text follows. Florian Weimer of Red Hat Product Security discovered that libvdpau, the VDPAU wrapper library, did not properly validate environment variables, allowing local attackers to gain additional privileges.