CVE-2005-0109
Vulnerability Summary
Timeline
Description
Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.
CVSS Metrics
- v3.0•MEDIUM•Score: 5.6CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
- v2.0•MEDIUM•Score: 4.7AV:L/AC:M/Au:N/C:C/I:N/A:N
EPSS Trends
Current EPSS score: 0.14%• Percentile: 34%
Affected Systems
- freebsd•freebsd
1.1.5.1 | 2.0 | 2.0.5 | 2.1.0 | 2.1.5 | 2.1.6 | 2.1.6.1 | 2.1.7.1 | 2.2 | 2.2.2 | 2.2.3 | 2.2.4 | 2.2.5 | 2.2.6 | 2.2.8 | 3.0 | 3.0:releng | 3.1 | 3.2 | 3.3 | 3.4 | 3.5 | 3.5:stable | 3.5.1 | 3.5.1:release | 3.5.1:stable | 4.0 | 4.0:alpha | 4.0:releng | 4.1 | 4.1.1 | 4.1.1:release | 4.1.1:stable | 4.2 | 4.2:stable | 4.3 | 4.3:release | 4.3:release_p38 | 4.3:releng | 4.3:stable | 4.4 | 4.4:release_p42 | 4.4:releng | 4.4:stable | 4.5 | 4.5:release | 4.5:release_p32 | 4.5:releng | 4.5:stable | 4.6 | 4.6:release | 4.6:release_p20 | 4.6:releng | 4.6:stable | 4.6.2 | 4.7 | 4.7:release | 4.7:release_p17 | 4.7:releng | 4.7:stable | 4.8 | 4.8:pre-release | 4.8:release_p6 | 4.8:releng | 4.9 | 4.9:pre-release | 4.9:releng | 4.10 | 4.10:release | 4.10:release_p8 | 4.10:releng | 4.11:release_p3 | 4.11:releng | 5.0 | 5.0:alpha | 5.0:release_p14 | 5.0:releng | 5.1 | 5.1:alpha | 5.1:release | 5.1:release_p5 | 5.1:releng | 5.2 | 5.2.1:release | 5.2.1:releng | 5.3 | 5.3:release | 5.3:releng | 5.3:stable | 5.4:pre-release
- redhat•enterprise_linux
2.1 | 3.0 | 4.0
- redhat•enterprise_linux_desktop
3.0 | 4.0
- redhat•fedora_core
core_3.0
- sco•openserver
5.0.7
- sco•unixware
7.1.3 | 7.1.3_up | 7.1.4
- sun•solaris
7.0 | 8.0 | 9.0 | 9.0:x86_update_2 | 10.0
- ubuntu•ubuntu_linux
4.1 | 5.04
References (18)
- http://www.kb.cert.org/vuls/id/911878
- http://secunia.com/advisories/18165
- http://www-1.ibm.com/support/docview.wss?uid=isg1SSRVHMCHMC_C081516_754
- http://marc.info/?l=freebsd-hackers&m=110994026421858&w=2
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.24/SCOSA-2005.24.txt
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9747
- http://www.vupen.com/english/advisories/2005/3002
- http://secunia.com/advisories/15348
- http://www.securityfocus.com/bid/12724
- http://marc.info/?l=freebsd-security&m=110994370429609&w=2
- http://www.redhat.com/support/errata/RHSA-2005-476.html
- http://securitytracker.com/id?1013967
- http://www.vupen.com/english/advisories/2005/0540
- http://www.daemonology.net/papers/htt.pdf
- http://www.redhat.com/support/errata/RHSA-2005-800.html
- http://www.daemonology.net/hyperthreading-considered-harmful/
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101739-1
- http://marc.info/?l=openbsd-misc&m=110995101417256&w=2