CVE-2007-3532

NameCVE-2007-3532
SourceCVE (at NVD; RH)
DescriptionNVIDIA drivers (nvidia-drivers) before 1.0.7185, 1.0.9639, and 100.14.11, as used in Gentoo Linux and possibly other distributions, creates /dev/nvidia* device files with insecure permissions, which allows local users to modify video card settings, cause a denial of service (crash or physical video card damage), and obtain sensitive information.
NVD severityhigh (attack range: local)
Debian Bugs434398
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot known to be vulnerable.
Debian/unstablenot known to be vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nvidia-kernel-common (PTS)lenny/contrib20080825+1fixed
squeeze/contrib20100522+1fixed

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nvidia-kernel-commonsource(unstable)20051028+1-0.1low434398

Notes

[sarge] - nvidia-kernel-common <no-dsa> (Contrib and non-free not supported)
[etch] - nvidia-kernel-common <no-dsa> (Contrib and non-free not supported)

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Imprint