安全研究
安全漏洞
多个CPU硬件信息泄露漏洞(CVE-2017-5715)
发布日期:2018-01-03
更新日期:2018-05-23
受影响系统:
Intel Corporation Xeon CPU E5-1650 v3 0描述:
BUGTRAQ ID: 102376
CVE(CAN) ID: CVE-2017-5715
CPU hardware是运行在中央处理器中用于管理和控制CPU的固件。
系统中微处理器若利用推测执行及间接分支预测,则实现中存在安全漏洞,可使本地攻击者通过旁道分析,利用该漏洞读取内存信息。包括Apple;Google;Intel;Linux Kernel;Microsoft;Mozilla等在内的多家厂商CUP硬件和操作系统受到影响。
<*来源:vendor
*>
建议:
厂商补丁:
Intel Corporation
-----------------
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:URL:https://www.exploit-db.com/exploits/43427/
MLIST:[debian-lts-announce] 20180502 [SECURITY] [DLA 1369-1] linux security update
URL:https://lists.debian.org/debian-lts-announce/2018/05/msg00000.html
https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html
https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html
https://spectreattack.com/
http://packetstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.html
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00088&languageid=en-fr
http://nvidia.custhelp.com/app/answers/detail/a_id/4609
http://xenbits.xen.org/xsa/advisory-254.html
https://access.redhat.com/security/vulnerabilities/speculativeexecution
https://aws.amazon.com/de/security/security-bulletins/AWS-2018-013/
https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/
https://developer.arm.com/support/arm-security-updates/speculative-processor-vulnerability
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002
https://support.f5.com/csp/article/K91229003
https://support.lenovo.com/us/en/solutions/LEN-18282
https://www.suse.com/c/suse-addresses-meltdown-spectre-vulnerabilities/
https://www.synology.com/support/security/Synology_SA_18_01
https://support.citrix.com/article/CTX231399
https://security.netapp.com/advisory/ntap-20180104-0001/
http://nvidia.custhelp.com/app/answers/detail/a_id/4611
http://nvidia.custhelp.com/app/answers/detail/a_id/4613
http://nvidia.custhelp.com/app/answers/detail/a_id/4614
https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html
https://www.vmware.com/us/security/advisories/VMSA-2018-0004.html
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03805en_us
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-001.txt
https://www.vmware.com/security/advisories/VMSA-2018-0007.html
https://securityadvisories.paloaltonetworks.com/Home/Detail/121
https://cert.vde.com/en-us/advisories/vde-2018-002
https://cert.vde.com/en-us/advisories/vde-2018-003
CISCO:20180104 CPU Side-Channel Information Disclosure Vulnerabilities
URL:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180104-cpusidechannel
DEBIAN:DSA-4120
URL:https://www.debian.org/security/2018/dsa-4120
DEBIAN:DSA-4187
URL:https://www.debian.org/security/2018/dsa-4187
DEBIAN:DSA-4188
URL:https://www.debian.org/security/2018/dsa-4188
FREEBSD:FreeBSD-SA-18:03
URL:https://security.FreeBSD.org/advisories/FreeBSD-SA-18:03.speculative_execution.asc
REDHAT:RHSA-2018:0292
URL:https://access.redhat.com/errata/RHSA-2018:0292
SUSE:SUSE-SU-2018:0006
URL:http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00002.html
SUSE:SUSE-SU-2018:0007
URL:http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00003.html
SUSE:SUSE-SU-2018:0008
URL:http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00004.html
SUSE:SUSE-SU-2018:0009
URL:http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00005.html
SUSE:SUSE-SU-2018:0010
URL:http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.html
SUSE:SUSE-SU-2018:0011
URL:http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html
SUSE:SUSE-SU-2018:0012
URL:http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.html
SUSE:SUSE-SU-2018:0019
URL:http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00012.html
SUSE:SUSE-SU-2018:0020
URL:http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00013.html
SUSE:openSUSE-SU-2018:0013
URL:http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00009.html
SUSE:openSUSE-SU-2018:0022
URL:http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.html
SUSE:openSUSE-SU-2018:0023
URL:http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html
UBUNTU:USN-3516-1
URL:https://usn.ubuntu.com/usn/usn-3516-1/
UBUNTU:USN-3531-1
URL:https://usn.ubuntu.com/3531-1/
UBUNTU:USN-3549-1
URL:https://usn.ubuntu.com/3549-1/
UBUNTU:USN-3560-1
URL:https://usn.ubuntu.com/3560-1/
UBUNTU:USN-3561-1
URL:https://usn.ubuntu.com/3561-1/
UBUNTU:USN-3580-1
URL:https://usn.ubuntu.com/3580-1/
UBUNTU:USN-3581-1
URL:https://usn.ubuntu.com/3581-1/
UBUNTU:USN-3581-2
URL:https://usn.ubuntu.com/3581-2/
UBUNTU:USN-3582-1
URL:https://usn.ubuntu.com/3582-1/
UBUNTU:USN-3582-2
URL:https://usn.ubuntu.com/3582-2/
UBUNTU:USN-3594-1
URL:https://usn.ubuntu.com/3594-1/
UBUNTU:USN-3597-1
URL:https://usn.ubuntu.com/3597-1/
UBUNTU:USN-3597-2
URL:https://usn.ubuntu.com/3597-2/
UBUNTU:USN-3542-2
URL:https://usn.ubuntu.com/3542-2/
UBUNTU:USN-3540-2
URL:https://usn.ubuntu.com/3540-2/
UBUNTU:USN-3541-2
URL:https://usn.ubuntu.com/3541-2/
UBUNTU:USN-3531-3
URL:https://usn.ubuntu.com/3531-3/
UBUNTU:USN-3620-2
URL:https://usn.ubuntu.com/3620-2/
CERT-VN:VU#584653
URL:http://www.kb.cert.org/vuls/id/584653
CERT-VN:VU#180049
URL:https://www.kb.cert.org/vuls/id/180049
BID:102376
URL:http://www.securityfocus.com/bid/102376
SECTRACK:1040071
URL:http://www.securitytracker.com/id/1040071
浏览次数:2854
严重程度:0(网友投票)
绿盟科技给您安全的保障