CVE-2005-0109
Last modified
CVE-2005-0109 is a medium-severity vulnerability rated 5.6/10 on the CVSS scale. Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.. EPSS estimates a 0.51% chance of exploitation in the next 30 days.
Description
Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.
Metrics
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Freebsd | Freebsd | 1.1.5.1 | — |
| Freebsd | Freebsd | 2.0 | — |
| Freebsd | Freebsd | 2.0.5 | — |
| Freebsd | Freebsd | 2.1.0 | — |
| Freebsd | Freebsd | 2.1.5 | — |
| Freebsd | Freebsd | 2.1.6 | — |
| Freebsd | Freebsd | 2.1.6.1 | — |
| Freebsd | Freebsd | 2.1.7.1 | — |
| Freebsd | Freebsd | 2.2 | — |
| Freebsd | Freebsd | 2.2.2 | — |
| Freebsd | Freebsd | 2.2.3 | — |
| Freebsd | Freebsd | 2.2.4 | — |
| Freebsd | Freebsd | 2.2.5 | — |
| Freebsd | Freebsd | 2.2.6 | — |
| Freebsd | Freebsd | 2.2.8 | — |
| Freebsd | Freebsd | 3.0 | — |
| Freebsd | Freebsd | 3.1 | — |
| Freebsd | Freebsd | 3.2 | — |
| Freebsd | Freebsd | 3.3 | — |
| Freebsd | Freebsd | 3.4 | — |
| Freebsd | Freebsd | 3.5 | — |
| Freebsd | Freebsd | 3.5.1 | — |
| Freebsd | Freebsd | 4.0 | — |
| Freebsd | Freebsd | 4.1 | — |
| Freebsd | Freebsd | 4.1.1 | — |
| Freebsd | Freebsd | 4.2 | — |
| Freebsd | Freebsd | 4.3 | — |
| Freebsd | Freebsd | 4.4 | — |
| Freebsd | Freebsd | 4.5 | — |
| Freebsd | Freebsd | 4.6 | — |
| Freebsd | Freebsd | 4.6.2 | — |
| Freebsd | Freebsd | 4.7 | — |
| Freebsd | Freebsd | 4.8 | — |
| Freebsd | Freebsd | 4.9 | — |
| Freebsd | Freebsd | 4.10 | — |
| Freebsd | Freebsd | 4.11 | Release P3 |
| Freebsd | Freebsd | 5.0 | — |
| Freebsd | Freebsd | 5.1 | — |
| Freebsd | Freebsd | 5.2 | — |
| Freebsd | Freebsd | 5.2.1 | Release |
| Freebsd | Freebsd | 5.3 | — |
| Freebsd | Freebsd | 5.4 | Pre-Release |
| Redhat | Enterprise Linux | 2.1 | — |
| Redhat | Enterprise Linux | 3.0 | — |
| Redhat | Enterprise Linux | 4.0 | — |
| Redhat | Enterprise Linux Desktop | 3.0 | — |
| Redhat | Enterprise Linux Desktop | 4.0 | — |
| Redhat | Fedora Core | core_3.0 | — |
| Sco | Openserver | 5.0.7 | — |
| Sco | Unixware | 7.1.3 | — |
Showing 50 of 58 affected configurations. See NVD for the full list.
References
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.24/SCOSA-2005.24.txtThird Party Advisory
- http://secunia.com/advisories/15348Permissions Required
- http://secunia.com/advisories/18165Permissions Required
- http://securitytracker.com/id?1013967Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.daemonology.net/hyperthreading-considered-harmful/Third Party Advisory
- http://www.daemonology.net/papers/htt.pdfThird Party Advisory
- http://www.kb.cert.org/vuls/id/911878Third Party Advisory, US Government Resource
- http://www.redhat.com/support/errata/RHSA-2005-476.htmlNot Applicable
- http://www.redhat.com/support/errata/RHSA-2005-800.htmlNot Applicable
- http://www.securityfocus.com/bid/12724Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.vupen.com/english/advisories/2005/0540Permissions Required
- http://www.vupen.com/english/advisories/2005/3002Permissions Required
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.24/SCOSA-2005.24.txtThird Party Advisory
- http://secunia.com/advisories/15348Permissions Required
- http://secunia.com/advisories/18165Permissions Required
- http://securitytracker.com/id?1013967Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.daemonology.net/hyperthreading-considered-harmful/Third Party Advisory
- http://www.daemonology.net/papers/htt.pdfThird Party Advisory
- http://www.kb.cert.org/vuls/id/911878Third Party Advisory, US Government Resource
- http://www.redhat.com/support/errata/RHSA-2005-476.htmlNot Applicable
- http://www.redhat.com/support/errata/RHSA-2005-800.htmlNot Applicable
- http://www.securityfocus.com/bid/12724Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.vupen.com/english/advisories/2005/0540Permissions Required
- http://www.vupen.com/english/advisories/2005/3002Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-0109?
How severe is CVE-2005-0109?
How do I fix CVE-2005-0109?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-0103PHP remote file inclusion vulnerability in webmail.php in Sq…
- CVE-2005-0104Cross-site scripting (XSS) vulnerability in webmail.php in S…
- CVE-2005-0105Unknown vulnerability in typespeed 0.4.1 and earlier allows …
- CVE-2005-0106SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/en…
- CVE-2005-0107bsmtpd 2.3 and earlier does not properly sanitize e-mail add…
- CVE-2005-0108Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow re…
- CVE-2005-0110Internet Explorer 6 on Windows XP SP2 allows remote attacker…
- CVE-2005-0111Stack-based buffer overflow in the websql CGI program in MyS…
- CVE-2005-0112The web-based administrative interface for 3Com OfficeConnec…
- CVE-2005-0113inpview in SGI IRIX allows local users to execute arbitrary …
- CVE-2005-0114vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneA…
- CVE-2005-0115Stack-based buffer overflow in DataRescue Interactive Disass…
Are you affected by CVE-2005-0109?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
