CVE-2005-0109
Last modified
CVE-2005-0109 is a medium-severity vulnerability rated 5.6/10 on the CVSS scale. Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.. EPSS estimates a 0.51% chance of exploitation in the next 30 days.
Description
Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.
Metrics
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Freebsd | Freebsd | 1.1.5.1 | — |
| Freebsd | Freebsd | 2.0 | — |
| Freebsd | Freebsd | 2.0.5 | — |
| Freebsd | Freebsd | 2.1.0 | — |
| Freebsd | Freebsd | 2.1.5 | — |
| Freebsd | Freebsd | 2.1.6 | — |
| Freebsd | Freebsd | 2.1.6.1 | — |
| Freebsd | Freebsd | 2.1.7.1 | — |
| Freebsd | Freebsd | 2.2 | — |
| Freebsd | Freebsd | 2.2.2 | — |
| Freebsd | Freebsd | 2.2.3 | — |
| Freebsd | Freebsd | 2.2.4 | — |
| Freebsd | Freebsd | 2.2.5 | — |
| Freebsd | Freebsd | 2.2.6 | — |
| Freebsd | Freebsd | 2.2.8 | — |
| Freebsd | Freebsd | 3.0 | — |
| Freebsd | Freebsd | 3.1 | — |
| Freebsd | Freebsd | 3.2 | — |
| Freebsd | Freebsd | 3.3 | — |
| Freebsd | Freebsd | 3.4 | — |
| Freebsd | Freebsd | 3.5 | — |
| Freebsd | Freebsd | 3.5.1 | — |
| Freebsd | Freebsd | 4.0 | — |
| Freebsd | Freebsd | 4.1 | — |
| Freebsd | Freebsd | 4.1.1 | — |
| Freebsd | Freebsd | 4.2 | — |
| Freebsd | Freebsd | 4.3 | — |
| Freebsd | Freebsd | 4.4 | — |
| Freebsd | Freebsd | 4.5 | — |
| Freebsd | Freebsd | 4.6 | — |
| Freebsd | Freebsd | 4.6.2 | — |
| Freebsd | Freebsd | 4.7 | — |
| Freebsd | Freebsd | 4.8 | — |
| Freebsd | Freebsd | 4.9 | — |
| Freebsd | Freebsd | 4.10 | — |
| Freebsd | Freebsd | 4.11 | Release P3 |
| Freebsd | Freebsd | 5.0 | — |
| Freebsd | Freebsd | 5.1 | — |
| Freebsd | Freebsd | 5.2 | — |
| Freebsd | Freebsd | 5.2.1 | Release |
| Freebsd | Freebsd | 5.3 | — |
| Freebsd | Freebsd | 5.4 | Pre-Release |
| Redhat | Enterprise Linux | 2.1 | — |
| Redhat | Enterprise Linux | 3.0 | — |
| Redhat | Enterprise Linux | 4.0 | — |
| Redhat | Enterprise Linux Desktop | 3.0 | — |
| Redhat | Enterprise Linux Desktop | 4.0 | — |
| Redhat | Fedora Core | core_3.0 | — |
| Sco | Openserver | 5.0.7 | — |
| Sco | Unixware | 7.1.3 | — |
Showing 50 of 58 affected configurations. See NVD for the full list.
References
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.24/SCOSA-2005.24.txtThird Party Advisory
- http://secunia.com/advisories/15348Permissions Required
- http://secunia.com/advisories/18165Permissions Required
- http://securitytracker.com/id?1013967Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.daemonology.net/hyperthreading-considered-harmful/Third Party Advisory
- http://www.daemonology.net/papers/htt.pdfThird Party Advisory
- http://www.kb.cert.org/vuls/id/911878Third Party Advisory, US Government Resource
- http://www.redhat.com/support/errata/RHSA-2005-476.htmlNot Applicable
- http://www.redhat.com/support/errata/RHSA-2005-800.htmlNot Applicable
- http://www.securityfocus.com/bid/12724Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.vupen.com/english/advisories/2005/0540Permissions Required
- http://www.vupen.com/english/advisories/2005/3002Permissions Required
- ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.24/SCOSA-2005.24.txtThird Party Advisory
- http://secunia.com/advisories/15348Permissions Required
- http://secunia.com/advisories/18165Permissions Required
- http://securitytracker.com/id?1013967Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.daemonology.net/hyperthreading-considered-harmful/Third Party Advisory
- http://www.daemonology.net/papers/htt.pdfThird Party Advisory
- http://www.kb.cert.org/vuls/id/911878Third Party Advisory, US Government Resource
- http://www.redhat.com/support/errata/RHSA-2005-476.htmlNot Applicable
- http://www.redhat.com/support/errata/RHSA-2005-800.htmlNot Applicable
- http://www.securityfocus.com/bid/12724Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.vupen.com/english/advisories/2005/0540Permissions Required
- http://www.vupen.com/english/advisories/2005/3002Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-0109?
How severe is CVE-2005-0109?
How do I fix CVE-2005-0109?
Are you affected by CVE-2005-0109?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
