CVE-2013-0131
published 2013-04-08CVE-2013-0131: Buffer overflow in the NVIDIA GPU driver before 304.88, 310.x before 310.44, and 313.x before 313.30 for the X Window System on UNIX, when NoScanout mode is…
PriorityP337high7.1CVSS 2.0
AVNACHAuSCCICAC
EPSS
4.81%
91.0th percentile
Buffer overflow in the NVIDIA GPU driver before 304.88, 310.x before 310.44, and 313.x before 313.30 for the X Window System on UNIX, when NoScanout mode is enabled, allows remote authenticated users to execute arbitrary code via a large ARGB cursor.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nvidia-graphics-drivers | < nvidia-graphics-drivers 304.88-1 (bookworm) | nvidia-graphics-drivers 304.88-1 (bookworm) |
| nvidia | gpu_driver | <= 304.00 | — |
| nvidia | gpu_driver | — | — |
| nvidia | gpu_driver | — | — |
| nvidia | gpu_driver | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:H/Au:S/C:C/I:C/A:C
osv7.1HIGH
vendor_debian7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
NVIDIA graphics drivers vulnerability
vendor_ubuntu·2013-04-10
CVE-2013-0131 NVIDIA graphics drivers vulnerability
Title: NVIDIA graphics drivers vulnerability
Summary: NVIDIA graphics drivers could be made to run programs as an administrator.
It was discovered that the NVIDIA graphics drivers incorrectly handled
large ARGB cursors. A local attacker could use this issue to gain root
privileges.
The NVIDIA graphics drivers have been updated to 304.88 to fix this issue.
In addition to the security fix, the updated packages contain bug fixes,
new features, and possibly incompatible changes.
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Debian
CVE-2013-0131: nvidia-graphics-drivers - Buffer overflow in the NVIDIA GPU driver before 304.88, 310.x before 310.44, and...
vendor_debian·2013·CVSS 7.1
CVE-2013-0131 [HIGH] CVE-2013-0131: nvidia-graphics-drivers - Buffer overflow in the NVIDIA GPU driver before 304.88, 310.x before 310.44, and...
Buffer overflow in the NVIDIA GPU driver before 304.88, 310.x before 310.44, and 313.x before 313.30 for the X Window System on UNIX, when NoScanout mode is enabled, allows remote authenticated users to execute arbitrary code via a large ARGB cursor.
Scope: local
bookworm: resolved (fixed in 304.88-1)
bullseye: resolved (fixed in 304.88-1)
forky: resolved (fixed in 304.88-1)
sid: resolved (fixed in 304.88-1)
trixie: resolved (fixed in 304.88-1)
GHSA
GHSA-x6cw-56pv-f6pj: Buffer overflow in the NVIDIA GPU driver before 304
ghsa_unreviewed·2022-05-05
CVE-2013-0131 [HIGH] CWE-119 GHSA-x6cw-56pv-f6pj: Buffer overflow in the NVIDIA GPU driver before 304
Buffer overflow in the NVIDIA GPU driver before 304.88, 310.x before 310.44, and 313.x before 313.30 for the X Window System on UNIX, when NoScanout mode is enabled, allows remote authenticated users to execute arbitrary code via a large ARGB cursor.
OSV
CVE-2013-0131: Buffer overflow in the NVIDIA GPU driver before 304
osv·2013-04-08·CVSS 7.1
CVE-2013-0131 [HIGH] CVE-2013-0131: Buffer overflow in the NVIDIA GPU driver before 304
Buffer overflow in the NVIDIA GPU driver before 304.88, 310.x before 310.44, and 313.x before 313.30 for the X Window System on UNIX, when NoScanout mode is enabled, allows remote authenticated users to execute arbitrary code via a large ARGB cursor.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://nvidia.custhelp.com/app/answers/detail/a_id/3290http://security.gentoo.org/glsa/glsa-201304-01.xmlhttp://www.kb.cert.org/vuls/id/771620http://www.nvidia.com/object/product-security.htmlhttp://nvidia.custhelp.com/app/answers/detail/a_id/3290http://security.gentoo.org/glsa/glsa-201304-01.xmlhttp://www.kb.cert.org/vuls/id/771620http://www.nvidia.com/object/product-security.html
2013-04-08
Published