(Sun Issues Fix for Solaris) FreeBSD Hyper-Threading Technology Support May Disclose Information to Local Users
|
|
SecurityTracker Alert ID: 1016210 |
|
SecurityTracker URL: http://securitytracker.com/id/1016210
|
|
CVE Reference:
CVE-2005-0109
(Links to External Site)
|
Date: Jun 2 2006
|
Impact:
Disclosure of authentication information, Disclosure of system information, Disclosure of user information, Root access via local system, User access via local system
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): Solaris 7, 8, 9, 10
|
Description:
A vulnerability was reported in FreeBSD when using Hyper-Threading Technology. A local user may be able to obtain elevated privileges. Sun Solaris is affected.
A local user may be able to obtain potentially sensitive information. In "many cases," this may be exploited to gain elevated privileges.
The vendor credits Colin Percival with reporting this vulnerability.
|
Impact:
A local user may be able to obtain information, leading to privilege escalation.
|
Solution:
Sun has described workarounds for Sun Solaris, which is affected by this vulnerability.
The workarounds are listed in the Sun advisory, available at:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101739-1
|
Vendor URL: sunsolve.sun.com/search/document.do?assetkey=1-26-101739-1 (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Fri, 2 Jun 2006 00:51:01 -0400
Subject: Simultaneous Multi-Threading Processors May Leak Information
|
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101739-1
CAN-2005-0109
CVE-2005-0109
|
|