MGASA-2015-0407
Dashboard / Vulnerabilities / MGASA-2015-0407
Summary: Updated nvidia driver packages fix security vulnerability
Details: A vulnerability has been found in the nvidia proprietary driver that could be used to allow a local, non-privileged user to corrupt kernel memory. This could be used to gain local root privileges. A local user can issue a specially crafted IOCTL to write a 32-bit integer value stored in the kernel driver to a user-specified memory location, potentially in the kernel address space. The user has a limited ability to influence the value of the integer that is written. (CVE-2015-5950)
References: https://advisories.mageia.org/MGASA-2015-0407.html, https://bugs.mageia.org/show_bug.cgi?id=16903, http://nvidia.custhelp.com/app/answers/detail/a_id/3763/~/cve-2015-5950-memory-corruption-due-to-an-unsanitized-pointer-in-the-nvidia
Affected packages
Package
Name: ldetect-lst
Purl: pkg:rpm/mageia/ldetect-lst?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
