1. Computers
  2. Display Drivers
  3. Graphics Cards
  4. Memory
  5. Motherboards
  6. Processors
  7. Software
  8. Storage
  9. Operating Systems


Facebook RSS Twitter Twitter Google Plus


Phoronix Test Suite

OpenBenchmarking.org

NVIDIA Has New Driver Update To Fix Security Flaw

NVIDIA

Published on 03 April 2013 01:04 AM EDT
Written by Fatima Sheremetyeva in NVIDIA
1 Comment

NVIDIA released the 313.30 Linux graphics driver on Tuesday night to take care of a security vulnerability.

Similar to past special-case releases to address security vulnerabilities with NVIDIA's binary blob, the 313.30 driver release officially just contains one security-related fix:
Fixed CVE-2013-0131: NVIDIA UNIX GPU Driver ARGB Cursor Buffer Overflow in "NoScanout" Mode. This buffer overflow, which occurred when an X client installed a large ARGB cursor on an X server running in NoScanout mode, could cause a denial of service (e.g., an X server segmentation fault), or could be exploited to achieve arbitrary code execution.
Details on this important NVIDIA driver security bug, which also hit FreeBSD and Solaris OS users, can be found in their customer portal. The good news is that this only affects those using the NoScanOut mode.

This security vulnerability that could take advantage of the X.Org Server generally running as the root user has affected NVIDIA users for a long while -- since the 195.22 driver days, or more easily known as late 2009. This is the first high-profile NVIDIA security driver bug in a few months, but last year they had some issues covered by Michael's NVIDIA Fixes Linux GPU Driver Security Hole and NVIDIA 295.40 Closes High-Risk Security Flaw.

This latest NVIDIA Linux graphics driver can be fetched from NVIDIA.com and is classified as a "certified" Linux GPU driver release.

Latest Linux Hardware Reviews
  1. Even With Re-Clocking, Nouveau Remains Behind NVIDIA's Proprietary Linux Driver
  2. The Power Consumption & Efficiency Of Open-Source GPU Drivers
  3. AMD R600g/RadeonSI Performance On Linux 3.16 With Mesa 10.3-devel
  4. Intel Pentium G3258 On Linux
Latest Linux Articles
  1. Updated Source Engine Benchmarks On The Latest AMD/NVIDIA Linux Drivers
  2. Nouveau vs. Radeon vs. Intel Tests On Linux 3.16, Mesa 10.3-devel
  3. KVM Benchmarks On Ubuntu 14.10
  4. X.Org Server 1.16 Officially Released With Terrific Features
Latest Linux News
  1. OpenSUSE Factory Turns Into Rolling Release Distribution
  2. "The World's Most Highly-Assured OS" Kernel Open-Sourced
  3. NVIDIA Is Working Towards VDPAU H.265/HEVC Support
  4. Hawaii Bug-Fixes Start Hitting Mainline RadeonSI Gallium3D
  5. The FFmpeg vs. Libav War Continues In Debian Land
  6. Grand Theft Auto Running On Direct3D Natively On Linux Shows Gallium3D Potential
  7. GCC As A Just-In Time Compiler Is An Interesting Project
  8. Age Of Wonders III Is Still Being Ported To Linux
  9. Git 2.1 To Further Mainline Windows Support Patches
  10. Debian 8.0 Jessie Is Settling For Linux 3.16
Latest Forum Discussions
  1. Updated and Optimized Ubuntu Free Graphics Drivers
  2. Debian + radeonsi
  3. Open-source drivers on ATI R7 260X
  4. List of Linux friendly Kickstarter projects
  5. Linus Torvalds On GCC 4.9: Pure & Utter Crap
  6. Porting Mesa to the Playstation 2
  7. ASRock AM1H-ITX: One Of The Best AM1 Mini-ITX Motherboards
  8. Table test