CVE-2017-0310
published 2017-02-15CVE-2017-0310: All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper access controls allowing unprivileged user to…
PriorityP421medium6.5CVSS 3.0
AVLACLPRLUINSCCNINAH
EPSS
0.28%
19.8th percentile
All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper access controls allowing unprivileged user to cause a denial of service.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nvidia-graphics-drivers | < nvidia-graphics-drivers 375.39-1 (bookworm) | nvidia-graphics-drivers 375.39-1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-340xx | < nvidia-graphics-drivers 375.39-1 (bookworm) | nvidia-graphics-drivers 375.39-1 (bookworm) |
| nvidia_corporation | gpu_display_driver | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c3xh-rcgh-wg6r: All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper access controls allowing unprivilege
ghsa_unreviewed·2022-05-13
CVE-2017-0310 [MEDIUM] CWE-269 GHSA-c3xh-rcgh-wg6r: All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper access controls allowing unprivilege
All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper access controls allowing unprivileged user to cause a denial of service.
OSV
CVE-2017-0310: All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper access controls allowing unprivilege
osv·2017-02-15·CVSS 6.5
CVE-2017-0310 [MEDIUM] CVE-2017-0310: All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper access controls allowing unprivilege
All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper access controls allowing unprivileged user to cause a denial of service.
Debian
CVE-2017-0310: nvidia-graphics-drivers - All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel ...
vendor_debian·2017·CVSS 6.5
CVE-2017-0310 [MEDIUM] CVE-2017-0310: nvidia-graphics-drivers - All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel ...
All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper access controls allowing unprivileged user to cause a denial of service.
Scope: local
bookworm: resolved (fixed in 375.39-1)
bullseye: resolved (fixed in 375.39-1)
forky: resolved (fixed in 375.39-1)
sid: resolved (fixed in 375.39-1)
trixie: resolved (fixed in 375.39-1)
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: IrfanView Jpeg2000 Reference Tile width Arbitrary Code Execution Vulnerability
blogs_talos·2017-04-26·CVSS 8.8
CVE-2017-2813 [HIGH] Vulnerability Spotlight: IrfanView Jpeg2000 Reference Tile width Arbitrary Code Execution Vulnerability
Discovered by Aleksandar Nikolic of Cisco Talos
### Overview
Talos is disclosing TALOS-2017-0310 / CVE-2017-2813, an arbitrary code execution vulnerability in the JP2 plugin for IrfanView image viewer. IrfanView is a widely used, Windows based, image viewing and editing application.
This particular vulnerability is in the jpeg2000 plugin (JP2) for IrfanView resulting in an integer overflow which leads to a wrong memory allocation and eventual arbitrary code execution. This vulnerability is specifically related to the way in which the plugin leverages the reference tile width value in a buffer size allocation. There are insufficient checks being done which can result in a small buffer being allocated for a large tile. This results in a controlled out of bounds write vulnerability. This o
Talos
Vulnerability Spotlight: IrfanView Jpeg2000 Reference Tile width Arbitrary Code Execution Vulnerability
blogs_talos·2017-04-26·CVSS 8.8
CVE-2017-2813 [HIGH] Vulnerability Spotlight: IrfanView Jpeg2000 Reference Tile width Arbitrary Code Execution Vulnerability
## Vulnerability Spotlight: IrfanView Jpeg2000 Reference Tile width Arbitrary Code Execution Vulnerability
Discovered by Aleksandar Nikolic of Cisco Talos
## Overview
Talos is disclosing TALOS-2017-0310 / CVE-2017-2813, an arbitrary code execution vulnerability in the JP2 plugin for IrfanView image viewer. IrfanView is a widely used, Windows based, image viewing and editing application.
This particular vulnerability is in the jpeg2000 plugin (JP2) for IrfanView resulting in an integer overflow which leads to a wrong memory allocation and eventual arbitrary code execution. This vulnerability is specifically related to the way in which the plugin leverages the reference tile width value in a buffer size allocation. There are insufficient checks being done which can result in a small buff
2017-02-15
Published