VDB
BDU%3A2018-01636
BDU%3A2018-01636
PUBLISHED
CVSS 4.900000095367432 MEDIUM
Уязвимость процессоров Intel архитектур Skylake и Kaby Lake, связанная с ошибками реализации технологии одновременной многопоточности (SMT), позволяющая нарушителю раскрыть защищаемую информацию
Risk Scores
CVSS 2.0
4.900000095367432
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical Ltd., ООО «РусБИТех-Астра», Oracle Corp., Red Hat Inc., Сообщество свободного программного обеспечения, Novell Inc., IBM Corp., Intel Corp., Node.js Foundation, OpenSSL Software Foundation | Ubuntu, Astra Linux Special Edition (запись в едином реестре российских программ №369), API Gateway, Red Hat Enterprise Linux, Debian GNU/Linux, OpenSUSE Leap, IBM Vios, IBM Aix, Enterprise Manager Ops Center, Intel Kaby Lake, rhvm-appliance, redhat-virtualization-host, Tuxedo, PeopleSoft Enterprise PeopleTools, Primavera P6 Enterprise Project Portfolio Management, Suse Linux Enterprise Desktop, SUSE Enterprise Storage, SUSE Linux Enterprise Server for SAP Applications, SUSE Linux Enterprise Software Development Kit, SUSE OpenStack Cloud, SUSE Linux Enterprise Module for Open Buildservice Development Tools, Suse Linux Enterprise Server, Node.js, SUSE Linux Enterprise Module for Web Scripting, Secure Global Desktop, Enterprise Manager Base Platform, Application Server, MySQL Enterprise Backup, SUSE Studio Onsite, SUSE CaaS Platform, SUSE Linux Enterprise Point of Sale, SUSE Linux Enterprise Module for Legacy Software, SUSE OpenStack Cloud Crowbar, OpenStack Cloud Magnum Orchestration, Red Hat Enterprise Virtualization, SUSE Linux Enterprise High Performance Computing, OpenSSL |
Timeline
- Dec 28, 2018 CVE Published
- Feb 19, 2025 CVE Updated
References
- https://xakep.ru/2018/11/02/portsmash/ url
- https://access.redhat.com/security/cve/cve-2018-5407 url
- https://www.securityfocus.com/bid/105897 url
- https://usn.ubuntu.com/3840-1/ url
- https://nvd.nist.gov/vuln/detail/CVE-2018-5407 url
- https://security-tracker.debian.org/tracker/CVE-2018-5407 url
- https://github.com/bbbrumley/portsmash url
- https://wiki.astralinux.ru/pages/viewpage.action?pageId=1212483 url
- https://wiki.astralinux.ru/astra-linux-se16-bulletin-20220829SE16 url
- https://www.oracle.com/security-alerts/public-vuln-to-advisory-mapping.html advisory
- https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/ advisory
- https://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-5407.html advisory
- https://www.suse.com/security/cve/CVE-2018-5407 advisory
- https://wiki.astralinux.ru/pages/viewpage.action?pageId=57444186 advisory