Lucene search

K
ubuntuUbuntuUSN-377-1
HistoryNov 04, 2006 - 12:00 a.m.

NVIDIA vulnerability

2006-11-0400:00:00
ubuntu.com
31

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.413

Percentile

97.3%

Releases

  • Ubuntu 6.10
  • Ubuntu 6.06

Details

Derek Abdine discovered that the NVIDIA Xorg driver did not correctly
verify the size of buffers used to render text glyphs. When displaying
very long strings of text, the Xorg server would crash. If a user were
tricked into viewing a specially crafted series of glyphs, this flaw
could be exploited to run arbitrary code with root privileges.

OSVersionArchitecturePackageVersionFilename
Ubuntu6.10noarchnvidia-glx< 2.6.17.6-1UNKNOWN
Ubuntu6.06noarchnvidia-glx< 2.6.15.12-1UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.413

Percentile

97.3%