|
|
Subscribe / Log in / New account

"Report" of fix unclear

"Report" of fix unclear

Posted Oct 16, 2006 22:43 UTC (Mon) by AJWM (guest, #15888)
Parent article: Local root exploit in NVidia driver

The reported fix in beta versions is a fix for a bug causing a driver crash. The release notes do not specifically mention the exploit. The beta may or may not fix the exploit, independent test results are not in.

I've seen several references that Lonni Friedman, who authored the message linked to as the report on the beta fix, works in PR for Nvidia, although the email itself has a gmail address.

Since the source is closed, verifying the fix is kinda tough.

Myself, I run graphics hardware based on the latest chip for which ATI released the specs (9250), (Nvidia has never released specs) using open source drivers.


to post comments

"Report" of fix unclear

Posted Oct 16, 2006 23:09 UTC (Mon) by drag (guest, #31333) [Link] (1 responses)

I got my Intel GMA950 and my ATI x800 that run open source drivers.

Thank goodness I got rid of my nvidia video card a while ago.

Hopefully the 'beta' drivers have the real fix. A lot of people should be already using them since they are suppose to support the AIGLX extensions compiz-related stuff.

"Report" of fix unclear

Posted Oct 16, 2006 23:17 UTC (Mon) by charris (guest, #13263) [Link]

The beta drivers also need to be unpacked and modified for the latest fedora 6 kernels. The kernel include file config.h no longer exists.

"Report" of fix unclear

Posted Oct 16, 2006 23:57 UTC (Mon) by Ed_L. (guest, #24287) [Link] (2 responses)

To be fair, I believe Lonnie Friedman works the Linux thread on Nvidia's support forum. In that respect he is part of Nvidia PR. But he is also a highly competent and helpful support engineer.

Not commenting on drivers. (Fond hopes the native ati driver in FC6 supports xinerama or dual view on my x700 card notwithstanding :-)

"Report" of fix unclear

Posted Oct 17, 2006 0:24 UTC (Tue) by drag (guest, #31333) [Link]

The open source ATI driver _should_ support it, unless there is some bug that prevents it from happenning, I think.

I don't have a dual monitor setup anymore so I don't know if it's do-able.

http://librarian.launchpad.net/3024460/xorg.conf

------

on a unrelated-to-your-reply note
What people need to realise is that with Linux you can't depend on closed source drivers to keep your system secure and stable.

This Nvidia bug has been known since 2004. It took until July 2006 before Nvidia aknowledged it and they may or may not have fixed it with the beta release.

This thing is potentionally a remote root exploit...

I remember similar issues being brought up about the state of wireless drivers for Windows and OS X. Linux is not invunerable from those problems either when it comes to closed source wireless drivers.

"Report" of fix unclear

Posted Oct 17, 2006 6:36 UTC (Tue) by tajyrink (subscriber, #2750) [Link]

My PCI-E X800 has working dual monitor output with the "radeon" driver ("ati" is just a wrapper, but has problems understanding that the card is not ATI Mach64...), no problem. Haven't checked for a while if all my MergedFB, MetaModes and CRT2HSync/CRT2VRefresh -options are actually even absolutely required, but I just followed some instructions originally.


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds