Submitted by KeesCook on Fri, 2006-11-03 12:07
Referenced CVEs:
CVE-2006-5379
Description:
===========================================================
Ubuntu Security Notice USN-377-1 November 03, 2006
linux-restricted-modules-2.6.15, linux-restricted-modules-2.6.17 vulnerability
CVE-2006-5379
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
nvidia-glx 2.6.15.12-1
Ubuntu 6.10:
nvidia-glx 2.6.17.6-1
After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Details follow:
Derek Abdine discovered that the NVIDIA Xorg driver did not correctly
verify the size of buffers used to render text glyphs. When displaying
very long strings of text, the Xorg server would crash. If a user were
tricked into viewing a specially crafted series of glyphs, this flaw
could be exploited to run arbitrary code with root privileges.


