CVE Vulnerabilities

CVE-2017-0310

Improper Privilege Management

Published: Feb 15, 2017 | Modified: Oct 03, 2019
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CVSS 2.x
4.9 MEDIUM
AV:L/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper access controls allowing unprivileged user to cause a denial of service.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Gpu_driver Nvidia - (including) - (including)
Nvidia-graphics-drivers-173 Ubuntu precise *
Nvidia-graphics-drivers-173 Ubuntu trusty *
Nvidia-graphics-drivers-173-updates Ubuntu precise *
Nvidia-graphics-drivers-304 Ubuntu devel *
Nvidia-graphics-drivers-304 Ubuntu precise *
Nvidia-graphics-drivers-304 Ubuntu trusty *
Nvidia-graphics-drivers-304 Ubuntu xenial *
Nvidia-graphics-drivers-304 Ubuntu yakkety *
Nvidia-graphics-drivers-340 Ubuntu devel *
Nvidia-graphics-drivers-340 Ubuntu precise *
Nvidia-graphics-drivers-340 Ubuntu trusty *
Nvidia-graphics-drivers-340 Ubuntu xenial *
Nvidia-graphics-drivers-340 Ubuntu yakkety *
Nvidia-graphics-drivers-96 Ubuntu precise *
Nvidia-graphics-drivers-96-updates Ubuntu precise *

Potential Mitigations

References