Bug 921280 (CVE-2015-1170) - VUL-0: CVE-2015-1170: The NVIDIA Display Driver R304 before 309.08, R340 before 341.44, R343 before345.20, and R346 befor...
Summary: VUL-0: CVE-2015-1170: The NVIDIA Display Driver R304 before 309.08, R340 befo...
Status: RESOLVED INVALID
Alias: CVE-2015-1170
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P2 - High : Normal
Target Milestone: ---
Assignee: Stefan Dirsch
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/114522/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-03-09 10:10 UTC by Marcus Meissner
Modified: 2015-03-09 12:40 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2015-03-09 10:10:39 UTC
CVE-2015-1170

The NVIDIA Display Driver R304 before 309.08, R340 before 341.44, R343 before
345.20, and R346 before 347.52 does not properly validate local client
impersonation levels when performing a "kernel administrator check," which
allows local users to gain administrator privileges via unspecified API calls.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-1170
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1170
http://www.cvedetails.com/cve/CVE-2015-1170/
http://nvidia.custhelp.com/app/answers/detail/a_id/3634


(please make sure nvidia has updated the drivers)
Comment 1 Stefan Dirsch 2015-03-09 10:29:44 UTC
We're providing via NVIDIA's ftp/http server:

304.125
340.76
346.47

There aren't any more recent drivers avaialble via

  http://www.nvidia.com/object/unix.html

Are we talking about a Windows only issue?
Comment 2 Marcus Meissner 2015-03-09 12:40:43 UTC
the nvidia custhelp page has no Linux reference and seems to exclusively refer to Windows.

so not for us.