|Main Archive Page > Month Archives > full-disclosure-uk archives|
A vulnerability has been discovered in the NVIDIA graphic drivers, allowing for a Denial of Service.
The NVIDIA drivers provide support for NVIDIA graphic boards.
Gregory Shikhman discovered that the default Gentoo setup of NVIDIA drivers creates the /dev/nvidia* with insecure file permissions.
A local attacker could send arbitrary values into the devices, possibly resulting in hardware damage on the graphic board or a Denial of Service.
There is no known workaround at this time.
All NVIDIA drivers users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose "x11-drivers/nvidia-drivers"
[ 1 ] CVE-2007-3532
This GLSA and any updates to it are available for viewing at the Gentoo Security Website:
Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to email@example.com or alternatively, you may file a bug at http://bugs.gentoo.org.
Copyright 2007 Gentoo Foundation, Inc; referenced text belongs to its owner(s).
The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license.