Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-0117

Опубликовано: 12 нояб. 2019
Источник: redhat
CVSS3: 6

Описание

Insufficient access control in protected memory subsystem for Intel(R) SGX for 6th, 7th, 8th, 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Xeon(R) Processor E3-1500 v5, v6 Families; Intel(R) Xeon(R) E-2100 & E-2200 Processor Families with Intel(R) Processor Graphics may allow a privileged user to potentially enable information disclosure via local access.

A flaw was found in the implementation of SGX around the access control of protected memory. This flaw allows a local attacker of a system with SGX enabled and an affected intel GPU with the ability to execute code to interpret the contents of the SGX protected memory.

Отчет

Red Hat Product Security is aware of this issue. Updates will be released as they become available. For additional information, please refer to the Red Hat Knowledgebase article: https://access.redhat.com/solutions/2019-microcode-nov

Меры по смягчению последствий

As of this time there are no known mitigations. Please install relevant updated packages to address this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5microcode_ctlWill not fix
Red Hat Enterprise Linux 6microcode_ctlFixedRHEA-2019:384712.11.2019
Red Hat Enterprise Linux 6.5 Advanced Update Supportmicrocode_ctlFixedRHEA-2019:385412.11.2019
Red Hat Enterprise Linux 6.6 Advanced Update Supportmicrocode_ctlFixedRHEA-2019:385312.11.2019
Red Hat Enterprise Linux 7microcode_ctlFixedRHEA-2019:384612.11.2019
Red Hat Enterprise Linux 7.2 Advanced Update Supportmicrocode_ctlFixedRHEA-2019:385212.11.2019
Red Hat Enterprise Linux 7.2 Telco Extended Update Supportmicrocode_ctlFixedRHEA-2019:385212.11.2019
Red Hat Enterprise Linux 7.2 Update Services for SAP Solutionsmicrocode_ctlFixedRHEA-2019:385212.11.2019
Red Hat Enterprise Linux 7.3 Advanced Update Supportmicrocode_ctlFixedRHEA-2019:385112.11.2019
Red Hat Enterprise Linux 7.3 Telco Extended Update Supportmicrocode_ctlFixedRHEA-2019:385112.11.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1220->CWE-200

6 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
nvd
около 6 лет назад

Insufficient access control in protected memory subsystem for Intel(R) SGX for 6th, 7th, 8th, 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Xeon(R) Processor E3-1500 v5, v6 Families; Intel(R) Xeon(R) E-2100 & E-2200 Processor Families with Intel(R) Processor Graphics may allow a privileged user to potentially enable information disclosure via local access.

github
больше 3 лет назад

Insufficient access control in protected memory subsystem for Intel(R) SGX for 6th, 7th, 8th, 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Xeon(R) Processor E3-1500 v5, v6 Families; Intel(R) Xeon(R) E-2100 & E-2200 Processor Families with Intel(R) Processor Graphics may allow a privileged user to potentially enable information disclosure via local access.

CVSS3: 6
fstec
около 6 лет назад

Уязвимость микропрограммного обеспечения процессоров Intel, связанная с недостатками контроля доступа, позволяющая нарушителю раскрыть защищаемую информацию

6 Medium

CVSS3