Utenti nvidia: attenti!
Tue Oct 17 16:18:36 CEST 2006
Tue Oct 17 17:34:04 CEST 2006 SluxOMG!
The _nv000053X function iterates over the glyph list and copies
glyph data into the buffer using each glyph's accumulated width,
xOff, height, and yOff values to calculate the destination position
in the buffer. The NVIDIA binary blob driver does not check this
calculation against the size of the allocated buffer. As a result,
a short sequence of user-supplied glyphs can be used to trick the
function into writing to an arbitrary location in memory.
...
It is important to note that glyph data is supplied to the X server
by the X client. Any remote X client can gain root privileges on
the X server using the proof of concept program attached.
It is also trivial to exploit this vulnerability as a DoS by causing
an existing X client program (such as Firefox) to render a long text
string. It may be possible to use Flash movies, Java applets, or
embedded web fonts to supply the custom glyph data necessary for
reliable remote code execution.
A simple HTML page containing an INPUT field with a long value is
sufficient to demonstrate the DoS.

NUBBI!
Tue Oct 17 18:07:47 CEST 2006 pixelnetPer Fortuna che ho una ATI

Anche se trovo i driver proprietari per Linux non proprio esaltanti!
Tue Oct 17 18:46:11 CEST 2006 estypure io

Tue Oct 17 20:11:54 CEST 2006 peoroHo un'nvidia da tre giorni...
Per me han trovato quel bug cercando d'entrarmi nel portatile novo

Sun Nov 05 13:54:48 CET 2006 FedeXXBeh se è stato segnalato probabilmente è un bug già corretto nei driver beta che uso io

Mon Nov 06 12:49:30 CET 2006 Vertigo
Se usi i beta 96xx, si'. Ma anche se usi gli ultimi 8778.