CVE-2006-5379
The accelerated rendering functionality of NVIDIA Binary Graphics Driver (binary blob driver) For Linux v8774 and v8762, and probably on other operating systems, allows local and remote attackers to execute arbitrary code via a large width value in a…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 26.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The accelerated rendering functionality of NVIDIA Binary Graphics Driver (binary blob driver) For Linux v8774 and v8762, and probably on other operating systems, allows local and remote attackers to execute arbitrary code via a large width value in a font glyph, which can be used to overwrite arbitrary memory locations.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 26.66% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- nvidia/binary graphics driver
- Source
- cve@mitre.org
References
- http://download2.rapid7.com/r7-0025/
- http://download2.rapid7.com/r7-0025/nv_exploit.cExploit
- http://nvidia.custhelp.com/cgi-bin/nvidia.cfg/php/enduser/std_adp.php?p_faqid=1971
- http://secunia.com/advisories/22419Vendor Advisory
- http://secunia.com/advisories/22676
- http://secunia.com/advisories/22730
- http://secunia.com/advisories/22764
- http://secunia.com/advisories/23678
- http://security.gentoo.org/glsa/glsa-200611-03.xml
- http://securityreason.com/securityalert/1742
- http://securitytracker.com/id?1017072
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102693-1
- http://www.kb.cert.org/vuls/id/147252US Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:007
- http://www.rapid7.com/advisories/R7-0025.jspVendor Advisory
- http://www.securityfocus.com/archive/1/448860/100/0/threaded
- http://www.securityfocus.com/archive/1/451329/100/0/threaded
- http://www.securityfocus.com/bid/20559
- http://www.ubuntu.com/usn/usn-377-1
- http://www.vupen.com/english/advisories/2006/4053
- http://www.vupen.com/english/advisories/2006/4328
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29622
- http://download2.rapid7.com/r7-0025/
- http://download2.rapid7.com/r7-0025/nv_exploit.cExploit
- http://nvidia.custhelp.com/cgi-bin/nvidia.cfg/php/enduser/std_adp.php?p_faqid=1971
- http://secunia.com/advisories/22419Vendor Advisory
- http://secunia.com/advisories/22676
- http://secunia.com/advisories/22730
- http://secunia.com/advisories/22764
- http://secunia.com/advisories/23678
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.