MEDIUM · 5.6

CVE-2005-0109

Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, m...

Vulnerability Description

Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.

CVSS Score

5.6

MEDIUM

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
FreebsdFreebsd1.1.5.1
RedhatEnterprise Linux2.1
RedhatEnterprise Linux Desktop3.0
RedhatFedora Corecore_3.0
ScoOpenserver5.0.7
ScoUnixware7.1.3
SunSolaris7.0
UbuntuUbuntu Linux4.1

References

FAQ

What is CVE-2005-0109?

CVE-2005-0109 is a vulnerability with a CVSS score of 5.6 (MEDIUM). Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, m...

How severe is CVE-2005-0109?

CVE-2005-0109 has been rated MEDIUM with a CVSS base score of 5.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-0109?

Check the references section above for vendor advisories and patch information. Affected products include: Freebsd Freebsd, Redhat Enterprise Linux, Redhat Enterprise Linux Desktop, Redhat Fedora Core, Sco Openserver.