CVE-2018-5407
בינונית 4.7
תיאור (מקור, אנגלית)
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
מדדים
- CVSS 3.1
-
4.7 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N - CWE
- CWE-200, CWE-203
מוצרים מושפעים
canonical: ubuntu linux; debian: debian linux; nodejs: node.js; openssl: openssl; tenable: nessus; oracle: api gateway; oracle: application server; oracle: enterprise manager base platform; oracle: enterprise manager ops center; oracle: mysql enterprise backup; oracle: peoplesoft enterprise peopletools; oracle: primavera p6 enterprise project portfolio management; oracle: tuxedo; oracle: vm virtualbox; redhat: enterprise linux desktop
קישורים
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html PatchVendor Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html PatchVendor Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2020.html PatchThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html PatchThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2020.html PatchThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html PatchThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html PatchThird Party Advisory