安全研究
安全漏洞
多个CPU硬件信息泄露漏洞(CVE-2017-5754)
发布日期:2018-01-03
更新日期:2018-05-23
受影响系统:
Intel Corporation Xeon CPU E5-1650 v3 0描述:
BUGTRAQ ID: 102378
CVE(CAN) ID: CVE-2017-5754
CPU hardware是运行在中央处理器中用于管理和控制CPU的固件。
系统中微处理器若利用推测执行及间接分支预测,则实现中存在安全漏洞,可使本地攻击者通过旁道分析数据缓存,利用该漏洞读取内存信息。包括Apple;Google;Intel;Linux Kernel;Microsoft;Mozilla等在内的多家厂商CUP硬件和操作系统受到影响。
<*来源:vendor
*>
建议:
厂商补丁:
Intel Corporation
-----------------
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:
URL:https://lists.debian.org/debian-lts-announce/2018/01/msg00004.html
MISC:https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html
MISC:https://meltdownattack.com/
MISC:https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html
https://01.org/security/advisories/intel-oss-10003
http://nvidia.custhelp.com/app/answers/detail/a_id/4609
http://xenbits.xen.org/xsa/advisory-254.html
https://access.redhat.com/security/vulnerabilities/speculativeexecution
https://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/
https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/
https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002
https://support.f5.com/csp/article/K91229003
https://support.lenovo.com/us/en/solutions/LEN-18282
https://www.suse.com/c/suse-addresses-meltdown-spectre-vulnerabilities/
https://www.synology.com/support/security/Synology_SA_18_01
https://support.citrix.com/article/CTX231399
https://security.netapp.com/advisory/ntap-20180104-0001/
http://nvidia.custhelp.com/app/answers/detail/a_id/4611
http://nvidia.custhelp.com/app/answers/detail/a_id/4613
http://nvidia.custhelp.com/app/answers/detail/a_id/4614
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03805en_us
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txt
https://source.android.com/security/bulletin/2018-04-01
https://support.citrix.com/article/CTX234679
https://cert.vde.com/en-us/advisories/vde-2018-002
https://cert.vde.com/en-us/advisories/vde-2018-003
CISCO:20180104 CPU Side-Channel Information Disclosure Vulnerabilities
URL:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180104-cpusidechannel
DEBIAN:DSA-4078
URL:https://www.debian.org/security/2018/dsa-4078
DEBIAN:DSA-4082
URL:https://www.debian.org/security/2018/dsa-4082
DEBIAN:DSA-4120
URL:https://www.debian.org/security/2018/dsa-4120
FREEBSD:FreeBSD-SA-18:03
URL:https://security.FreeBSD.org/advisories/FreeBSD-SA-18:03.speculative_execution.asc
REDHAT:RHSA-2018:0292
URL:https://access.redhat.com/errata/RHSA-2018:0292
SUSE:SUSE-SU-2018:0010
URL:http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.html
SUSE:SUSE-SU-2018:0011
URL:http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html
SUSE:SUSE-SU-2018:0012
URL:http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.html
SUSE:openSUSE-SU-2018:0022
URL:http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.html
SUSE:openSUSE-SU-2018:0023
URL:http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html
UBUNTU:USN-3516-1
URL:https://usn.ubuntu.com/usn/usn-3516-1/
UBUNTU:USN-3522-2
URL:https://usn.ubuntu.com/usn/usn-3522-2/
UBUNTU:USN-3523-2
URL:https://usn.ubuntu.com/usn/usn-3523-2/
UBUNTU:USN-3524-2
URL:https://usn.ubuntu.com/usn/usn-3524-2/
UBUNTU:USN-3525-1
URL:https://usn.ubuntu.com/usn/usn-3525-1/
UBUNTU:USN-3522-3
URL:https://usn.ubuntu.com/3522-3/
UBUNTU:USN-3522-4
URL:https://usn.ubuntu.com/3522-4/
UBUNTU:USN-3523-1
URL:https://usn.ubuntu.com/3523-1/
UBUNTU:USN-3583-1
URL:https://usn.ubuntu.com/3583-1/
UBUNTU:USN-3597-1
URL:https://usn.ubuntu.com/3597-1/
UBUNTU:USN-3597-2
URL:https://usn.ubuntu.com/3597-2/
UBUNTU:USN-3540-2
URL:https://usn.ubuntu.com/3540-2/
UBUNTU:USN-3541-2
URL:https://usn.ubuntu.com/3541-2/
CERT-VN:VU#584653
URL:http://www.kb.cert.org/vuls/id/584653
CERT-VN:VU#180049
URL:https://www.kb.cert.org/vuls/id/180049
BID:102378
URL:http://www.securityfocus.com/bid/102378
SECTRACK:1040071
URL:http://www.securitytracker.com/id/1040071
浏览次数:2206
严重程度:0(网友投票)
绿盟科技给您安全的保障