Vulnerability Name:

CVE-2015-3625 (CCN-105015)

Assigned:2015-06-19
Published:2015-06-19
Updated:2019-06-13
Summary:The NVIDIA GPU driver for FreeBSD R352 before 352.09, 346 before 346.72, R349 before 349.16, R343 before 343.36, R340 before 340.76, R337 before 337.25, R334 before 334.21, R331 before 331.113, and R304 before 304.125 allows local users with certain permissions to read or write arbitrary kernel memory via unspecified vectors that trigger an untrusted pointer dereference.
CVSS v3 Severity:5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): 
Access Complexity (AC): 
Authentication (Au): 
Impact Metrics:Confidentiality (C): 
Integrity (I): 
Availibility (A): 
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): 
Access Complexity (AC): 
Athentication (Au): 
Impact Metrics:Confidentiality (C): 
Integrity (I): 
Availibility (A): 
Vulnerability Type:CWE-264
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2015-3625

Source: CCN
Type: NVIDIA Web site
CVE-2015-3625: Privilege Escalation via Unsanitized Pointer Dereference in NVIDIA FreeBSD Kernel Driver

Source: CONFIRM
Type: Patch, Vendor Advisory
http://nvidia.custhelp.com/app/answers/detail/a_id/3693

Source: SECTRACK
Type: Third Party Advisory, VDB Entry
1032981

Source: XF
Type: UNKNOWN
nvidia-cve20153625-priv-esc(105015)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:nvidia:gpu_driver:*:*:*:*:*:*:*:* (Version >= 304 and < 304.125)
  • OR cpe:/a:nvidia:gpu_driver:*:*:*:*:*:*:*:* (Version >= 331 and < 331.113)
  • OR cpe:/a:nvidia:gpu_driver:*:*:*:*:*:*:*:* (Version >= 334 and < 334.21)
  • OR cpe:/a:nvidia:gpu_driver:*:*:*:*:*:*:*:* (Version >= 337 and < 337.25)
  • OR cpe:/a:nvidia:gpu_driver:*:*:*:*:*:*:*:* (Version >= 340 and < 340.76)
  • OR cpe:/a:nvidia:gpu_driver:*:*:*:*:*:*:*:* (Version >= 343 and < 343.36)
  • OR cpe:/a:nvidia:gpu_driver:*:*:*:*:*:*:*:* (Version >= 346 and < 346.72)
  • OR cpe:/a:nvidia:gpu_driver:*:*:*:*:*:*:*:* (Version >= 349 and < 349.16)
  • OR cpe:/a:nvidia:gpu_driver:*:*:*:*:*:*:*:* (Version >= 352 and < 352.09)
  • AND
  • cpe:/o:freebsd:freebsd:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Vulnerability Name:

    CVE-2015-3625 (CCN-105330)

    Assigned:2015-06-16
    Published:2015-06-16
    Updated:2019-06-13
    Summary:The NVIDIA GPU driver for FreeBSD R352 before 352.09, 346 before 346.72, R349 before 349.16, R343 before 343.36, R340 before 340.76, R337 before 337.25, R334 before 334.21, R331 before 331.113, and R304 before 304.125 allows local users with certain permissions to read or write arbitrary kernel memory via unspecified vectors that trigger an untrusted pointer dereference.
    CVSS v3 Severity:9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
    Exploitability Metrics:Attack Vector (AV): Local
    Attack Complexity (AC): Low
    Privileges Required (PR): None
    User Interaction (UI): None
    Scope:Scope (S): Changed
    Impact Metrics:Confidentiality (C): High
    Integrity (I): High
    Availibility (A): High
    CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
    5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
    Exploitability Metrics:Access Vector (AV): 
    Access Complexity (AC): 
    Authentication (Au): 
    Impact Metrics:Confidentiality (C): 
    Integrity (I): 
    Availibility (A): 
    7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
    5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
    Exploitability Metrics:Access Vector (AV): 
    Access Complexity (AC): 
    Athentication (Au): 
    Impact Metrics:Confidentiality (C): 
    Integrity (I): 
    Availibility (A): 
    Vulnerability Type:CWE-264
    Vulnerability Consequences:Gain Privileges
    References:Source: MITRE
    Type: CNA
    CVE-2015-3625

    Source: CCN
    Type: NVIDIA Web site
    CVE-2015-3625: Privilege Escalation via Unsanitized Pointer Dereference in NVIDIA FreeBSD Kernel Driver

    Source: XF
    Type: UNKNOWN
    nvidia-freebsd-cve20153625-priv-esc(105330)

    BACK
    nvidia gpu driver *
    nvidia gpu driver *
    nvidia gpu driver *
    nvidia gpu driver *
    nvidia gpu driver *
    nvidia gpu driver *
    nvidia gpu driver *
    nvidia gpu driver *
    nvidia gpu driver *
    freebsd freebsd *