KernelTrap: Linux: NVIDIA Binary Graphics Driver Exploit
Oct 17, 2006, 13:30 (5 Talkback[s])
WEBINAR: On-demand Event
Replace Oracle with the NoSQL Engagement Database: Why and how leading companies are making the switch REGISTER >
"A recent security advisory announced today by Rapid7 explains,
'the NVIDIA Binary Graphics Driver for Linux is vulnerable to a
buffer overflow that allows an attacker to run arbitrary code as
root. This bug can be exploited both locally or remotely (via a
remote X client or an X client which visits a malicious web page).
A working proof-of-concept root exploit is attached to this
advisory.' The advisory goes on to note that the FreeBSD and
Solaris binary drivers are also likely vulnerable to the same flaw
and cautions, 'it is our opinion that NVIDIA's binary driver
remains an unacceptable security risk based on the large numbers of
reproducible, unfixed crashes that have been reported in public
forums and bug databases...'"