Originally posted by: n0cmonkey
Originally posted by: skrewler2
meant to say, being locally logged in OR root
No mention of requiring you to be root, or even logged in locally to the machine in the advisory. In fact, it mentions being able to remotely exploit this flaw. Please provide a link.
Also, how do you rationalize the fact nVidia sat on this vulnerability for 2 years? Or the fact it wasn't fixed in the release drivers at the time this vulnerability was released? Or how about the fact no one could fix this except nVidia?
EDIT: Just to be clear, the fact that the vulnerability exists is not a problem. People write code, and people make mistakes. The problem is that it took 2 years for this to come out to the public who are still WITHOUT A FIX. If this was an open source driver, it would have been fixed in 2k4.