Phoronix Forums  

Go Back   Phoronix Forums > Linux Graphics / X.Org Drivers > NVIDIA Linux

NVIDIA Linux Both NVIDIA's closed-source and open-source drivers can be discussed here.

Reply
 
Thread Tools Display Modes
  #1  
Old 10-16-2006, 06:18 PM
drag drag is offline
Senior Member
 
Join Date: Sep 2006
Posts: 227
Default

Oh, this is a nice one:
http://download2.rapid7.com/r7-0025/

Security vunerabilities in Nvidia binary drivers.

With active proof-of-concept exploit for Linux. This is not only a local vunerability with X + nvidia drivers, but it can be remotely exploitable.. for instance if your browsing to a malicious website it's possible for somebody to have your browser display something _which_could_give_them_root_access_.

This is a problem with how Nvidia accelerates rendering of text. This is a very very serious problem.

This bug has been around for years now. First reported in 2004 it took nearly 2 years for Nvidia to aknowledge the problem, which was in July 2006 and they still haven't fixed it.

To me this is headlines-style stuff.
Reply With Quote
  #2  
Old 10-16-2006, 06:51 PM
Michael Michael is offline
Phoronix
 
Join Date: Jun 2006
Location: United States
Posts: 4,564
Default

There is more information on the security exploit over @ Kernel Trap

The bug may be fixed in NVIDIA Beta 1.0-9625.
Reply With Quote
  #3  
Old 10-17-2006, 03:35 PM
Michael Michael is offline
Phoronix
 
Join Date: Jun 2006
Location: United States
Posts: 4,564
Default

For 1.0-8XXX series, the exploit can be fixed by throwing:

Option "RenderAccel" "False"

into the xorg.conf
Reply With Quote
  #4  
Old 10-19-2006, 04:08 PM
Michael Michael is offline
Phoronix
 
Join Date: Jun 2006
Location: United States
Posts: 4,564
Default

NVIDIA has released a statement on the matter:

http://nvidia.custhelp.com/cgi-bin/n...p?p_faqid=1971

The drivers at http://www.nvidia.com/object/unix.html now also contain a hotfix.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 03:23 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright ©2004 - 2009 by Phoronix Media.