=========================================================================Ubuntu Security Notice USN-2747-1
September 28, 2015

nvidia-graphics-drivers-304, nvidia-graphics-drivers-304-updates,
nvidia-graphics-drivers-340, nvidia-graphics-drivers-340-updates,
nvidia-graphics-drivers-346, nvidia-graphics-drivers-346-updates, jockey
vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.04
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

NVIDIA graphics drivers could be made to run programs as an administrator.

Software Description:
- nvidia-graphics-drivers-304: NVIDIA binary X.Org driver
- nvidia-graphics-drivers-304-updates: NVIDIA binary X.Org driver
- nvidia-graphics-drivers-340: NVIDIA binary X.Org driver
- nvidia-graphics-drivers-340-updates: NVIDIA binary X.Org driver
- nvidia-graphics-drivers-346: NVIDIA binary X.Org driver
- nvidia-graphics-drivers-346-updates: NVIDIA binary X.Org driver
- jockey: user interface and desktop integration for driver management

Details:

Dario Weisser discovered that the NVIDIA graphics drivers incorrectly
handled certain IOCTL writes. A local attacker could use this issue to
possibly gain root privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.04:
  nvidia-304                      304.128-0ubuntu0.1
  nvidia-304-updates              304.128-0ubuntu0.1
  nvidia-340                      340.93-0ubuntu0.1
  nvidia-340-updates              340.93-0ubuntu0.1
  nvidia-346                      346.96-0ubuntu0.1
  nvidia-346-updates              346.96-0ubuntu0.1

Ubuntu 14.04 LTS:
  nvidia-304                      304.128-0ubuntu0.0.1
  nvidia-304-updates              304.128-0ubuntu0.0.1
  nvidia-340                      340.93-0ubuntu0.0.1
  nvidia-340-updates              340.93-0ubuntu0.0.1
  nvidia-346                      346.96-0ubuntu0.0.1
  nvidia-346-updates              346.96-0ubuntu0.0.1

Ubuntu 12.04 LTS:
  jockey-common                   0.9.7-0ubuntu7.16
  nvidia-304                      304.128-0ubuntu0.0.0.1
  nvidia-304-updates              304.128-0ubuntu0.0.0.1
  nvidia-340                      340.93-0ubuntu0.0.0.1
  nvidia-340-updates              340.93-0ubuntu0.0.0.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-2747-1
  CVE-2015-5950

Package Information:

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.128-0ubuntu0.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304-updates/304.128-0ubuntu0.1
  https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-340/340.93-0ubuntu0.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-340-updates/340.93-0ubuntu0.1
  https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-346/346.96-0ubuntu0.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-346-updates/346.96-0ubuntu0.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.128-0ubuntu0.0.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304-updates/304.128-0ubuntu0.0.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-340/340.93-0ubuntu0.0.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-340-updates/340.93-0ubuntu0.0.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-346/346.96-0ubuntu0.0.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-346-updates/346.96-0ubuntu0.0.1
  https://launchpad.net/ubuntu/+source/jockey/0.9.7-0ubuntu7.16

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.128-0ubuntu0.0.0.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304-updates/304.128-0ubuntu0.0.0.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-340/340.93-0ubuntu0.0.0.1

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-340-updates/340.93-0ubuntu0.0.0.1


Ubuntu 2747-1: NVIDIA graphics drivers vulnerability

September 28, 2015
NVIDIA graphics drivers could be made to run programs as an administrator.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: nvidia-304 304.128-0ubuntu0.1 nvidia-304-updates 304.128-0ubuntu0.1 nvidia-340 340.93-0ubuntu0.1 nvidia-340-updates 340.93-0ubuntu0.1 nvidia-346 346.96-0ubuntu0.1 nvidia-346-updates 346.96-0ubuntu0.1 Ubuntu 14.04 LTS: nvidia-304 304.128-0ubuntu0.0.1 nvidia-304-updates 304.128-0ubuntu0.0.1 nvidia-340 340.93-0ubuntu0.0.1 nvidia-340-updates 340.93-0ubuntu0.0.1 nvidia-346 346.96-0ubuntu0.0.1 nvidia-346-updates 346.96-0ubuntu0.0.1 Ubuntu 12.04 LTS: jockey-common 0.9.7-0ubuntu7.16 nvidia-304 304.128-0ubuntu0.0.0.1 nvidia-304-updates 304.128-0ubuntu0.0.0.1 nvidia-340 340.93-0ubuntu0.0.0.1 nvidia-340-updates 340.93-0ubuntu0.0.0.1 After a standard system update you need to reboot your computer to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2747-1

CVE-2015-5950

Severity
September 28, 2015

Package Information

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.128-0ubuntu0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304-updates/304.128-0ubuntu0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-340/340.93-0ubuntu0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-340-updates/340.93-0ubuntu0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-346/346.96-0ubuntu0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-346-updates/346.96-0ubuntu0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.128-0ubuntu0.0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304-updates/304.128-0ubuntu0.0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-340/340.93-0ubuntu0.0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-340-updates/340.93-0ubuntu0.0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-346/346.96-0ubuntu0.0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-346-updates/346.96-0ubuntu0.0.1 https://launchpad.net/ubuntu/+source/jockey/0.9.7-0ubuntu7.16 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304/304.128-0ubuntu0.0.0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-304-updates/304.128-0ubuntu0.0.0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-340/340.93-0ubuntu0.0.0.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-340-updates/340.93-0ubuntu0.0.0.1

Related News