"Report" of fix unclear
"Report" of fix unclear
Posted Oct 16, 2006 22:43 UTC (Mon) by AJWM (guest, #15888)Parent article: Local root exploit in NVidia driver
The reported fix in beta versions is a fix for a bug causing a driver crash. The release notes do not specifically mention the exploit. The beta may or may not fix the exploit, independent test results are not in.
I've seen several references that Lonni Friedman, who authored the message linked to as the report on the beta fix, works in PR for Nvidia, although the email itself has a gmail address.
Since the source is closed, verifying the fix is kinda tough.
Myself, I run graphics hardware based on the latest chip for which ATI released the specs (9250), (Nvidia has never released specs) using open source drivers.
Posted Oct 16, 2006 23:09 UTC (Mon)
by drag (guest, #31333)
[Link] (1 responses)
Thank goodness I got rid of my nvidia video card a while ago.
Hopefully the 'beta' drivers have the real fix. A lot of people should be already using them since they are suppose to support the AIGLX extensions compiz-related stuff.
Posted Oct 16, 2006 23:17 UTC (Mon)
by charris (guest, #13263)
[Link]
Posted Oct 16, 2006 23:57 UTC (Mon)
by Ed_L. (guest, #24287)
[Link] (2 responses)
Not commenting on drivers. (Fond hopes the native ati driver in FC6 supports xinerama or dual view on my x700 card notwithstanding :-)
Posted Oct 17, 2006 0:24 UTC (Tue)
by drag (guest, #31333)
[Link]
I don't have a dual monitor setup anymore so I don't know if it's do-able.
http://librarian.launchpad.net/3024460/xorg.conf
------
on a unrelated-to-your-reply note
This Nvidia bug has been known since 2004. It took until July 2006 before Nvidia aknowledged it and they may or may not have fixed it with the beta release.
This thing is potentionally a remote root exploit...
I remember similar issues being brought up about the state of wireless drivers for Windows and OS X. Linux is not invunerable from those problems either when it comes to closed source wireless drivers.
Posted Oct 17, 2006 6:36 UTC (Tue)
by tajyrink (subscriber, #2750)
[Link]
I got my Intel GMA950 and my ATI x800 that run open source drivers."Report" of fix unclear
The beta drivers also need to be unpacked and modified for the latest fedora 6 kernels. The kernel include file config.h no longer exists."Report" of fix unclear
To be fair, I believe Lonnie Friedman works the Linux thread on Nvidia's support forum. In that respect he is part of Nvidia PR. But he is also a highly competent and helpful support engineer."Report" of fix unclear
The open source ATI driver _should_ support it, unless there is some bug that prevents it from happenning, I think."Report" of fix unclear
What people need to realise is that with Linux you can't depend on closed source drivers to keep your system secure and stable.
My PCI-E X800 has working dual monitor output with the "radeon" driver ("ati" is just a wrapper, but has problems understanding that the card is not ATI Mach64...), no problem. Haven't checked for a while if all my MergedFB, MetaModes and CRT2HSync/CRT2VRefresh -options are actually even absolutely required, but I just followed some instructions originally."Report" of fix unclear
