CVE-2017-5715
Systeme mit Mikroprozessoren, die spekulatives Ausführen und indirekte Befehlsvorhersage nutzen, können es einem Angreifer mit lokalen Be…
Description
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
Source: BSI CSAFBSI WID Portalcvelistv5
Metrics
99.5 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
none
79.17
PoC (publicly reported)
Published
2018-01-04 13:00 UTC
References & sources
- http://nvidia.custhelp.com/app/answers/detail/a_id/4609x_refsource_CONFIRM
- https://usn.ubuntu.com/3560-1/vendor-advisoryx_refsource_UBUNTU
- https://lists.debian.org/debian-lts-announce/2018/07/msg00015.htmlmailing-listx_refsource_MLIST
- https://www.debian.org/security/2018/dsa-4187vendor-advisoryx_refsource_DEBIAN
- https://usn.ubuntu.com/3542-2/vendor-advisoryx_refsource_UBUNTU
- https://security.gentoo.org/glsa/201810-06vendor-advisoryx_refsource_GENTOO
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlx_refsource_CONFIRM
- http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlx_refsource_CONFIRM
- https://usn.ubuntu.com/3540-2/vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/vulnerabilities/speculativeexecutionx_refsource_CONFIRM
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002x_refsource_CONFIRM
- https://lists.debian.org/debian-lts-announce/2018/09/msg00007.htmlmailing-listx_refsource_MLIST
- https://usn.ubuntu.com/3597-1/vendor-advisoryx_refsource_UBUNTU
- https://lists.debian.org/debian-lts-announce/2018/07/msg00016.htmlmailing-listx_refsource_MLIST
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.htmlvendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.htmlvendor-advisoryx_refsource_SUSE
- http://nvidia.custhelp.com/app/answers/detail/a_id/4611x_refsource_CONFIRM
- https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.htmlx_refsource_MISC
- https://www.debian.org/security/2018/dsa-4213vendor-advisoryx_refsource_DEBIAN
- https://cert.vde.com/en-us/advisories/vde-2018-002x_refsource_CONFIRM