PT-2017-1387 · Nvidia · Nvidia Gpu Driver
Published
2017-03-08
·
Updated
2019-10-03
·
CVE-2017-0307
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NVIDIA GPU driver versions prior to the fixed version
Description
The issue is related to insufficient access control in the NVIDIA GPU driver for the Android operating system, allowing a remote attacker to launch an application with the privileges of the current user. This could enable a local malicious application to execute arbitrary code within the context of the kernel, potentially leading to a local permanent device compromise.
Recommendations
For versions prior to the fixed version, consider restricting access to the kernel until a patch is available.
As a temporary workaround, avoid using the NVIDIA GPU driver for sensitive operations until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nvidia Gpu Driver