SB2018022105 - Multiple vulnerabilities in NVIDIA SHIELD TV



SB2018022105 - Multiple vulnerabilities in NVIDIA SHIELD TV

Published: February 21, 2018

Security Bulletin ID SB2018022105
Severity
Low
Patch available
YES
Number of vulnerabilities 8
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 8 secuirty vulnerabilities.


1) Out-of-bounds write (CVE-ID: CVE-2017-6282)

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists due to a flaw in NVMAP in NVIDIA Tegra kernel driver. A local attacker can trigger out-of-bounds write and execute arbitrary code with elevated privileges.

2) Privilege escalation (CVE-ID: CVE-2017-6279)

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists due to a flaw in OMX.Nvidia.aac.decoder in NVIDIA Tegra OpenMax Component. A local attacker can disable the dead code to avoid malicious software, instantiate the vulnerable component and cause service to crash or gain elevated privileges.

3) Out-of-bounds read (CVE-ID: CVE-2017-6295)

The vulnerability allows a local attacker to obtain potentially sensitive information or cause DoS condition on the target system.

The weakness exists due to a flaw in the Keymaster implementation in NVIDIA TrustZone Software. A local attacker can trigger out-of-bounds read and gain read access to important data or cause the service to crash.

4) Use-after-free error (CVE-ID: CVE-2017-13175)

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists due to a flaw in OMX.Nvidia.audio.render in NVIDIA Tegra OpenMax Component. A local attacker can use mediaserver, trigger use-after-free error, cause the service to crash or possibly gain elevated privileges.

5) Use-after-free error (CVE-ID: CVE-2017-6276)

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists due to a flaw in LIBNVMMLITE_VIDEO.SO in NVIDIA OpenMax Component. A local attacker can use mediaserver, trigger use-after-free error, cause the service to crash or possibly gain elevated privileges.

6) Information disclosure (CVE-ID: CVE-2017-6283)

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists due to a flaw in the RSA function in NVIDIA Security Engine. A local attacker can clear the keyslot read/write lock permissions on a chip reset and gain read access to important data.

7) Information disclosure (CVE-ID: CVE-2017-6284)

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists due to a flaw in the Deterministic Random Bit Generator (DRBG) in NVIDIA Security Engine due to improper initialization and storing or transmitting sensitive data using a weakened encryption scheme. A local attacker can gain read access to important data.

8) Privilege escalation (CVE-ID: CVE-2017-6296)

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists due to a TOCTOU issue in the DRM application in NVIDIA TrustZone Software. A local attacker can cause service to crash or gain elevated privileges.

Remediation

Install update from vendor's website.