Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-5754

Опубликовано: 04 янв. 2018
Источник: debian
EPSS Критический

Описание

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed4.14.12-1package
nvidia-graphics-driversfixed384.111-1package
nvidia-graphics-driversfixed384.111-4~deb9u1stretchpackage
nvidia-graphics-driversfixed340.106-1jessiepackage
nvidia-graphics-driversend-of-lifewheezypackage
nvidia-graphics-drivers-legacy-340xxfixed340.106-1package
nvidia-graphics-drivers-legacy-340xxfixed340.106-1~deb9u1stretchpackage
nvidia-graphics-drivers-legacy-304xxunfixedpackage
nvidia-graphics-drivers-legacy-304xxno-dsastretchpackage
nvidia-graphics-drivers-legacy-304xxno-dsajessiepackage
linux-grsecremovedpackage
xenfixed4.11.1~pre+1.733450b39b-1package
xenfixed4.8.3+comet2+shim4.10.0+comet3-1+deb9u4stretchpackage
xenignoredjessiepackage

Примечания

  • https://meltdownattack.com/

  • https://xenbits.xen.org/xsa/advisory-254.html

  • https://googleprojectzero.blogspot.co.uk/2018/01/reading-privileged-memory-with-side.html

  • http://blog.cyberus-technology.de/posts/2018-01-03-meltdown.html

  • Paper: https://meltdownattack.com/meltdown.pdf

  • https://01.org/security/advisories/intel-oss-10003

EPSS

Процентиль: 100%
0.92234
Критический

Связанные уязвимости

CVSS3: 5.6
ubuntu
больше 7 лет назад

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.

CVSS3: 5.5
redhat
больше 7 лет назад

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.

CVSS3: 5.6
nvd
больше 7 лет назад

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.

oracle-oval
больше 7 лет назад

ELSA-2018-4006: Unbreakable Enterprise kernel security update (IMPORTANT)

CVSS3: 5.6
fstec
больше 7 лет назад

Уязвимость процессоров Intel и АRM, вызванная ошибкой контроля доступа к памяти при спекулятивном выполнении инструкций процессора, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 100%
0.92234
Критический