You are here
Home > Preporuke > Sigurnosni nedostatak NVIDIA pogonskog programa

Sigurnosni nedostatak NVIDIA pogonskog programa

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-2814-1
November 18, 2015

nvidia-graphics-drivers-304, nvidia-graphics-drivers-304-updates,
nvidia-graphics-drivers-340, nvidia-graphics-drivers-340-updates,
nvidia-graphics-drivers-352, nvidia-graphics-drivers-352-updates vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 15.10
– Ubuntu 15.04
– Ubuntu 14.04 LTS
– Ubuntu 12.04 LTS

Summary:

NVIDIA graphics drivers could be made to run programs as an administrator.

Software Description:
– nvidia-graphics-drivers-304: NVIDIA binary X.Org driver
– nvidia-graphics-drivers-304-updates: NVIDIA binary X.Org driver
– nvidia-graphics-drivers-340: NVIDIA binary X.Org driver
– nvidia-graphics-drivers-340-updates: NVIDIA binary X.Org driver
– nvidia-graphics-drivers-352: NVIDIA binary X.Org driver
– nvidia-graphics-drivers-352-updates: NVIDIA binary X.Org driver

Details:

It was discovered that the NVIDIA graphics drivers incorrectly sanitized
user mode inputs. A local attacker could use this issue to possibly gain
root privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
nvidia-304 304.131-0ubuntu0.15.10.1
nvidia-304-updates 304.131-0ubuntu0.15.10.1
nvidia-331 340.96-0ubuntu0.15.10.1
nvidia-331-updates 340.96-0ubuntu0.15.10.1
nvidia-340 340.96-0ubuntu0.15.10.1
nvidia-340-updates 340.96-0ubuntu0.15.10.1
nvidia-346 352.63-0ubuntu0.15.10.1
nvidia-346-updates 352.63-0ubuntu0.15.10.1
nvidia-352 352.63-0ubuntu0.15.10.1
nvidia-352-updates 352.63-0ubuntu0.15.10.1

Ubuntu 15.04:
nvidia-304 304.131-0ubuntu0.15.04.1
nvidia-304-updates 304.131-0ubuntu0.15.04.1
nvidia-331 340.96-0ubuntu0.15.04.1
nvidia-331-updates 340.96-0ubuntu0.15.04.1
nvidia-340 340.96-0ubuntu0.15.04.1
nvidia-340-updates 340.96-0ubuntu0.15.04.1
nvidia-346 352.63-0ubuntu0.15.04.1
nvidia-346-updates 352.63-0ubuntu0.15.04.1
nvidia-352 352.63-0ubuntu0.15.04.1
nvidia-352-updates 352.63-0ubuntu0.15.04.1

Ubuntu 14.04 LTS:
nvidia-304 304.131-0ubuntu0.14.04.1
nvidia-304-updates 304.131-0ubuntu0.14.04.1
nvidia-331 340.96-0ubuntu0.14.04.1
nvidia-331-updates 340.96-0ubuntu0.14.04.1
nvidia-340 340.96-0ubuntu0.14.04.1
nvidia-340-updates 340.96-0ubuntu0.14.04.1
nvidia-346 352.63-0ubuntu0.14.04.1
nvidia-346-updates 352.63-0ubuntu0.14.04.1
nvidia-352 352.63-0ubuntu0.14.04.1
nvidia-352-updates 352.63-0ubuntu0.14.04.1

Ubuntu 12.04 LTS:
nvidia-304 304.131-0ubuntu0.12.04.1
nvidia-304-updates 304.131-0ubuntu0.12.04.1
nvidia-331-updates 340.96-0ubuntu0.12.04.1
nvidia-340 340.96-0ubuntu0.12.04.1
nvidia-340-updates 340.96-0ubuntu0.12.04.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2814-1
CVE-2015-7869

Package Information:

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.131-0ubuntu0.15.10.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304-updates/304.131-0ubuntu0.15.10.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-340/340.96-0ubuntu0.15.10.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-340-updates/340.96-0ubuntu0.15.10.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-352/352.63-0ubuntu0.15.10.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-352-updates/352.63-0ubuntu0.15.10.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.131-0ubuntu0.15.04.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304-updates/304.131-0ubuntu0.15.04.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-340/340.96-0ubuntu0.15.04.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-340-updates/340.96-0ubuntu0.15.04.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-352/352.63-0ubuntu0.15.04.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-352-updates/352.63-0ubuntu0.15.04.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.131-0ubuntu0.14.04.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304-updates/304.131-0ubuntu0.14.04.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-340/340.96-0ubuntu0.14.04.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-340-updates/340.96-0ubuntu0.14.04.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-352/352.63-0ubuntu0.14.04.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-352-updates/352.63-0ubuntu0.14.04.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.131-0ubuntu0.12.04.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304-updates/304.131-0ubuntu0.12.04.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-340/340.96-0ubuntu0.12.04.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-340-updates/340.96-0ubuntu0.12.04.1

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2

iQIcBAEBCgAGBQJWTNJPAAoJEGVp2FWnRL6TFAwQAJSM3iLL19zjBbQRMTPUsfDU
2PRUUa0PDxXK0R3onpY+EkHEq/Bq/INRIM2xYDlG8oze65rmq6y2xVI0WoWkxXTr
UXnAwkOpLdtYvwlnqwna8bpPsh4bwgyy6/J1fXmRze8MGble4cifxleWatJzIGO5
PojFf1/9rjuNZhFmPEFHKq6flu5cuxkNojddhwWQO/biVAww0cxHWr35Xcvtp7KG
NXp6d5FZqqYb+sas5xw6HMS0StfHWZ5TDoBv74elvpu5mCY4bvcSPP0yo6RnXS+j
4/5No00/yQs3FKV1sWKlSjZx1rxSXfNeoeraUCxg/Nq2o5eGc5lhuyzqHoGQYB3v
neytdTuF4JvD/bb/pxOvAWLmucHISJbgOEWkOeZewFr+WSls4uA8I+96DXJ5Av5V
GwdObfg2ju4ZIzIBLJwHfvbx0feLEip/I1KehUVPFDh7/xc/FssxCYYsNWrH871f
kTCIF1hKkykR6BsvcuJcIZLpOYLu5TQGrezAz1BOTt18Os8LcomRr49P618EotLX
9/qlM/D0Csg92wVzzicZXQxKoEFkUEkzS6wSlKd/dchKcOeQXmlkzq8TiAyjpauy
V1d1ceufGvPWZVtd12J4VRI2J5NnMV1XyhlFj6eQjwGnLCDdSU21uXAAKsDJrwZe
ZHh2VkLzKxMpyz28HDdC
=ZcSb
—–END PGP SIGNATURE—–

AutorMarijo Plepelic
Cert idNCERT-REF-2015-11-0011-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Ranjivost programskog paketa postgresql

Otkrivena je ranjivost u programskom paketu postgresql za RHEL 6. Ranjivost se nalazila u funkciji crypt (contrib/pgcrypto), a udaljenim napadačima...

Close