[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2018-5407Date: (C)2018-12-07   (M)2024-03-15


Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 4.7CVSS Score : 1.9
Exploit Score: 1.0Exploit Score: 3.4
Impact Score: 3.6Impact Score: 2.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector: LOCAL
Attack Complexity: HIGHAccess Complexity: MEDIUM
Privileges Required: LOWAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: NONE
Confidentiality: HIGHAvailability: NONE
Integrity: NONE 
Availability: NONE 
  
Reference:
BID-105897
EXPLOIT-DB-45785
DSA-4348
DSA-4355
GLSA-201903-10
N/A
RHSA-2019:0483
RHSA-2019:0651
RHSA-2019:0652
RHSA-2019:2125
RHSA-2019:3929
RHSA-2019:3931
RHSA-2019:3932
RHSA-2019:3933
RHSA-2019:3935
USN-3840-1
https://lists.debian.org/debian-lts-announce/2018/11/msg00024.html
https://eprint.iacr.org/2018/1060.pdf
https://github.com/bbbrumley/portsmash
https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/
https://security.netapp.com/advisory/ntap-20181126-0001/
https://support.f5.com/csp/article/K49711130?utm_source=f5support&%3Butm_medium=RSS
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
https://www.tenable.com/security/tns-2018-16
https://www.tenable.com/security/tns-2018-17

CPE    10
cpe:/o:debian:debian_linux:9.0
cpe:/a:openssl:openssl
cpe:/a:oracle:peoplesoft_enterprise_peopletools:8.55
cpe:/o:canonical:ubuntu_linux:16.04::~~lts~~~
...
CWE    1
CWE-203
OVAL    25
oval:org.secpod.oval:def:603589
oval:org.secpod.oval:def:1000719
oval:org.secpod.oval:def:1504481
oval:org.secpod.oval:def:53478
...

© SecPod Technologies