Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-5407

Опубликовано: 15 нояб. 2018
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 1.9
CVSS3: 4.7

Описание

Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.

РелизСтатусПримечание
bionic

released

1.1.0g-2ubuntu4.3
cosmic

not-affected

1.1.1-1ubuntu2
devel

not-affected

1.1.1-1ubuntu2
disco

not-affected

1.1.1-1ubuntu2
eoan

not-affected

1.1.1-1ubuntu2
esm-infra-legacy/trusty

not-affected

1.0.1f-1ubuntu2.27
esm-infra/bionic

not-affected

1.1.0g-2ubuntu4.3
esm-infra/focal

not-affected

1.1.1-1ubuntu2
esm-infra/xenial

not-affected

1.0.2g-1ubuntu4.14
focal

not-affected

1.1.1-1ubuntu2

Показывать по

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needs-triage]
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

Показывать по

РелизСтатусПримечание
bionic

released

1.0.2n-1ubuntu5.2
cosmic

released

1.0.2n-1ubuntu6.1
devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

1.0.2n-1ubuntu5.2
esm-infra/focal

DNE

focal

DNE

groovy

DNE

Показывать по

EPSS

Процентиль: 73%
0.00778
Низкий

1.9 Low

CVSS2

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
redhat
больше 6 лет назад

Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.

CVSS3: 4.7
nvd
больше 6 лет назад

Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.

CVSS3: 4.7
debian
больше 6 лет назад

Simultaneous Multi-threading (SMT) in processors can enable local user ...

CVSS3: 4.7
github
около 3 лет назад

Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.

oracle-oval
больше 6 лет назад

ELSA-2019-0483: openssl security and bug fix update (MODERATE)

EPSS

Процентиль: 73%
0.00778
Низкий

1.9 Low

CVSS2

4.7 Medium

CVSS3