Vulnerability CVE-2005-0109


Published: 2005-03-05   Modified: 2012-02-12

Description:
Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.

Type:

CWE-Other

CVSS2 => (AV:L/AC:M/Au:N/C:C/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.7/10
6.9/10
3.4/10
Exploit range
Attack complexity
Authentication
Local
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
None
None
Affected software
Ubuntu -> Ubuntu linux 
SUN -> Solaris 
SCO -> Openserver 
SCO -> Unixware 
Redhat -> Enterprise linux 
Redhat -> Enterprise linux desktop 
Redhat -> Fedora core 
Freebsd -> Freebsd 

 References:
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.24/SCOSA-2005.24.txt
http://marc.info/?l=freebsd-hackers&m=110994026421858&w=2
http://marc.info/?l=freebsd-security&m=110994370429609&w=2
http://marc.info/?l=openbsd-misc&m=110995101417256&w=2
http://securitytracker.com/id?1013967
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101739-1
http://www-1.ibm.com/support/docview.wss?uid=isg1SSRVHMCHMC_C081516_754
http://www.daemonology.net/hyperthreading-considered-harmful/
http://www.daemonology.net/papers/htt.pdf
http://www.kb.cert.org/vuls/id/911878
http://www.redhat.com/support/errata/RHSA-2005-476.html
http://www.redhat.com/support/errata/RHSA-2005-800.html
http://www.securityfocus.com/bid/12724
http://www.vupen.com/english/advisories/2005/0540
http://www.vupen.com/english/advisories/2005/3002
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9747

Copyright 2024, cxsecurity.com

 

Back to Top