tags 574255 + patch tags 574255 + security severity 574255 critical thanks Dear Randall,
I've prepared an NMU for nvidia-kernel-common (versioned as 20100216+3+nmu1). It fixes the security bug (tested). Moreover, if you delete debian/preinst (not used), the package will be lintian clean. Regards. -- Jean-Christophe Dubacq
diff -Nru nvidia-kernel-common-20100216+3/debian/changelog nvidia-kernel-common-20100216+3+nmu1/debian/changelog --- nvidia-kernel-common-20100216+3/debian/changelog 2010-02-21 22:38:31.000000000 +0100 +++ nvidia-kernel-common-20100216+3+nmu1/debian/changelog 2010-03-17 10:42:29.000000000 +0100 @@ -1,3 +1,10 @@ +nvidia-kernel-common (20100216+3+nmu1) unstable; urgency=critical + + * Non-maintainer upload. + * fix security bug for console users (closes: #574255) + + -- Jean-Christophe Dubacq <jcduba...@free.fr> Wed, 17 Mar 2010 10:42:23 +0100 + nvidia-kernel-common (20100216+3) unstable; urgency=low * fix executable nvidia_helper (closes: #570191) diff -Nru nvidia-kernel-common-20100216+3/debian/nvidia-kernel-common.udev nvidia-kernel-common-20100216+3+nmu1/debian/nvidia-kernel-common.udev --- nvidia-kernel-common-20100216+3/debian/nvidia-kernel-common.udev 2010-02-16 20:22:15.000000000 +0100 +++ nvidia-kernel-common-20100216+3+nmu1/debian/nvidia-kernel-common.udev 2010-03-17 10:16:10.000000000 +0100 @@ -2,7 +2,7 @@ # This is necessary until the driver uses some other form of auth ENV{ACL_MANAGE}=="0", GOTO="nvidia_end" DRIVER=="nvidia",ENV{NVIDIA_DEVICE}="1" -ENV{NVIDIA_DEVICE}=="0", GOTO="nvidia_end" +ENV{NVIDIA_DEVICE}!="1", GOTO="nvidia_end" ENV{ACL_MANAGE}="1" TEST!="/lib/libglib-2.0.so.0", GOTO="nvidia_end" # apply ACL for all locally logged in users