1. Computers
  2. Display Drivers
  3. Graphics Cards
  4. Memory
  5. Motherboards
  6. Processors
  7. Software
  8. Storage
  9. Operating Systems


Facebook RSS Twitter Twitter Google Plus


Phoronix Test Suite

OpenBenchmarking Benchmarking Platform
Phoromatic Test Orchestration

NVIDIA Has New Driver Update To Fix Security Flaw

NVIDIA

Published on 03 April 2013 01:04 AM EDT
Written by Fatima Sheremetyeva in NVIDIA
1 Comment

NVIDIA released the 313.30 Linux graphics driver on Tuesday night to take care of a security vulnerability.

Similar to past special-case releases to address security vulnerabilities with NVIDIA's binary blob, the 313.30 driver release officially just contains one security-related fix:
Fixed CVE-2013-0131: NVIDIA UNIX GPU Driver ARGB Cursor Buffer Overflow in "NoScanout" Mode. This buffer overflow, which occurred when an X client installed a large ARGB cursor on an X server running in NoScanout mode, could cause a denial of service (e.g., an X server segmentation fault), or could be exploited to achieve arbitrary code execution.
Details on this important NVIDIA driver security bug, which also hit FreeBSD and Solaris OS users, can be found in their customer portal. The good news is that this only affects those using the NoScanOut mode.

This security vulnerability that could take advantage of the X.Org Server generally running as the root user has affected NVIDIA users for a long while -- since the 195.22 driver days, or more easily known as late 2009. This is the first high-profile NVIDIA security driver bug in a few months, but last year they had some issues covered by Michael's NVIDIA Fixes Linux GPU Driver Security Hole and NVIDIA 295.40 Closes High-Risk Security Flaw.

This latest NVIDIA Linux graphics driver can be fetched from NVIDIA.com and is classified as a "certified" Linux GPU driver release.

Latest Linux News
  1. OpenWRT 15.05 Preparing Improved Security & Better Networking
  2. Using The New LLVM/Clang OpenMP Support
  3. Zapcc Claims To Be A "Much Faster C++ Compiler"
  4. Godot 1.1 Engine Release Brings New 2D Engine
  5. Intel VA-API Driver 1.6 Is Coming
  6. Canonical Is Reportedly Considering An IPO
  7. GNOME 3.18 - GTK3 Now Supports RandR 1.5
  8. Fedora 22 Risks Being Delayed Beyond Next Week
  9. Systemd 220 Has Finally Been Released
  10. LibreOffice 5.0 Beta 1 Released
  11. Allwinner Publishes New CedarX Open-Source Code
  12. ACPI 6 Non-Volatile Memory Device Support / NFIT / LIBND For Linux
Latest Articles & Reviews
  1. Btrfs RAID 0/1 Benchmarks On The Linux 4.1 Kernel
  2. The State Of Various Firefox Features
  3. Intel Iris Graphics Performance With Mesa 10.6
  4. Fedora Workstation 22 Is Looking Great, Running Fantastic
Most Viewed News This Week
  1. The Linux 4.0 Kernel Currently Has An EXT4 Corruption Issue
  2. Rust 1.0 Language Officially Released
  3. AMDGPU Open-Source Driver Code Continues Maturing
  4. Oculus Rift Suspends Linux Development To Focus On Windows
  5. Wine 1.7.43 Works On Desktop Shell Window Support
  6. Spec Ops: The Line Is The Latest Linux Shooter
  7. RadeonSI Gallium3D Driver To Be Enabled For Android
  8. Microsoft Open-Sources The Windows Communication Foundation