Gentoo Archives: gentoo-announce

From: Sergey Popov <pinkbyte@g.o>
To: gentoo-announce@g.o
Subject: [gentoo-announce] [ GLSA 201402-02 ] NVIDIA Drivers: Privilege Escalation
Date: Sun, 02 Feb 2014 19:00:21
Message-Id: 52EE8C3E.5010503@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201402-02
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: NVIDIA Drivers: Privilege Escalation
9 Date: February 02, 2014
10 Bugs: #493448
11 ID: 201402-02
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 A NVIDIA drivers bug allows unprivileged user-mode software to access
19 the GPU inappropriately, allowing for privilege escalation.
20
21 Background
22 ==========
23
24 The NVIDIA drivers provide X11 and GLX support for NVIDIA graphic
25 boards.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 x11-drivers/nvidia-drivers
34 < 331.20 *>= 304.116
35 *>= 319.76
36 >= 331.20
37
38 Description
39 ===========
40
41 The vulnerability is caused due to the driver allowing unprivileged
42 user-mode software to access the GPU.
43
44 Impact
45 ======
46
47 A local attacker could gain escalated privileges.
48
49 Workaround
50 ==========
51
52 There is no known workaround at this time.
53
54 Resolution
55 ==========
56
57 All NVIDIA Drivers users using the 331 branch should upgrade to the
58 latest version:
59
60 # emerge --sync
61 # emerge --ask --oneshot -v ">=x11-drivers/nvidia-drivers-331.20"
62
63 All NVIDIA Drivers users using the 319 branch should upgrade to the
64 latest version:
65
66 # emerge --sync
67 # emerge --ask --oneshot -v ">=x11-drivers/nvidia-drivers-319.76"
68
69 All NVIDIA Drivers users using the 304 branch should upgrade to the
70 latest version:
71
72 # emerge --sync
73 # emerge --ask --oneshot -v ">=x11-drivers/nvidia-drivers-304.116"
74
75 References
76 ==========
77
78 [ 1 ] CVE-2013-5986
79 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-5986
80 [ 2 ] CVE-2013-5987
81 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-5987
82
83 Availability
84 ============
85
86 This GLSA and any updates to it are available for viewing at
87 the Gentoo Security Website:
88
89 http://security.gentoo.org/glsa/glsa-201402-02.xml
90
91 Concerns?
92 =========
93
94 Security is a primary focus of Gentoo Linux and ensuring the
95 confidentiality and security of our users' machines is of utmost
96 importance to us. Any security concerns should be addressed to
97 security@g.o or alternatively, you may file a bug at
98 https://bugs.gentoo.org.
99
100 License
101 =======
102
103 Copyright 2014 Gentoo Foundation, Inc; referenced text
104 belongs to its owner(s).
105
106 The contents of this document are licensed under the
107 Creative Commons - Attribution / Share Alike license.
108
109 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature