PT-2017-1388 · Nvidia · Nvidia Gpu Driver
Nathan Crandall
·
Publicado
2017-03-08
·
Atualizado
2019-10-03
·
CVE-2017-0306
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NVIDIA GPU driver versions prior to the fixed version
Description
The issue is related to insufficient access control in the NVIDIA GPU driver for the Android operating system, allowing a remote attacker to launch an application with the privileges of the current user. A local malicious application can execute arbitrary code within the context of the kernel, potentially leading to a local permanent device compromise. This may require reflashing the operating system to repair the device.
Recommendations
For versions prior to the fixed version, consider restricting access to the kernel to minimize the risk of exploitation until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Nvidia Gpu Driver