CVE-2012-4225
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
19/11/2012
Last modified:
11/04/2025
Description
NVIDIA UNIX graphics driver before 295.71 and before 304.32 allows local users to write to arbitrary physical memory locations and gain privileges by modifying the VGA window using /dev/nvidia0.
Impact
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:nvidia:unix_graphic_driver:*:*:*:*:*:*:*:* | 295.71 (including) | |
cpe:2.3:a:nvidia:unix_graphic_driver:*:*:*:*:*:*:*:* | 304.32 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://nvidia.custhelp.com/app/answers/detail/a_id/3140
- http://seclists.org/fulldisclosure/2012/Aug/4
- http://seclists.org/fulldisclosure/2012/Aug/76
- http://security.gentoo.org/glsa/glsa-201304-01.xml
- http://www.openwall.com/lists/oss-security/2012/08/01/1
- http://www.openwall.com/lists/oss-security/2012/08/08/4
- http://nvidia.custhelp.com/app/answers/detail/a_id/3140
- http://seclists.org/fulldisclosure/2012/Aug/4
- http://seclists.org/fulldisclosure/2012/Aug/76
- http://security.gentoo.org/glsa/glsa-201304-01.xml
- http://www.openwall.com/lists/oss-security/2012/08/01/1
- http://www.openwall.com/lists/oss-security/2012/08/08/4