CVE-2018-5407
published 2018-11-15CVE-2018-5407: Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on…
PriorityP428medium4.7CVSS 3.1
AVLACHPRLUINSUCHINAN
EXPLOIT
EPSS
3.42%
87.6th percentile
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openssl | < openssl 1.1.1~~pre9-1 (bookworm) | openssl 1.1.1~~pre9-1 (bookworm) |
| nodejs | node.js | < 6.14.4 | 6.14.4 |
| nodejs | node.js | >= 10.0.0 < 10.9.0 | 10.9.0 |
| nodejs | node.js | >= 8.0.0 < 8.11.4 | 8.11.4 |
| openssl | openssl | >= 0 < 1.1.1~~pre9-1 | 1.1.1~~pre9-1 |
| openssl | openssl | >= 0 < 1.1.1~~pre9-1 | 1.1.1~~pre9-1 |
| openssl | openssl | >= 0 < 1.1.1~~pre9-1 | 1.1.1~~pre9-1 |
| openssl | openssl | >= 0 < 1.1.1~~pre9-1 | 1.1.1~~pre9-1 |
| openssl | openssl | >= 0 < 1.0.1f-1ubuntu2.27 | 1.0.1f-1ubuntu2.27 |
| openssl | openssl | >= 0 < 1.0.2g-1ubuntu4.14 | 1.0.2g-1ubuntu4.14 |
| openssl | openssl | >= 0 < 1.1.0g-2ubuntu4.3 | 1.1.0g-2ubuntu4.3 |
| openssl | openssl | >= 1.0.2 < 1.0.2q | 1.0.2q |
| openssl | openssl | >= 1.1.0 < 1.1.0i | 1.1.0i |
| oracle | api_gateway | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | enterprise_manager_base_platform | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_ubuntu5.9MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3rjg-j575-7f6p: Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing att
ghsa_unreviewed·2022-05-13
CVE-2018-5407 [MEDIUM] CWE-203 GHSA-3rjg-j575-7f6p: Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing att
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
OSV
openssl, openssl1.0 vulnerabilities
osv·2018-12-06·CVSS 5.9
CVE-2018-0734 [MEDIUM] openssl, openssl1.0 vulnerabilities
openssl, openssl1.0 vulnerabilities
Samuel Weiser discovered that OpenSSL incorrectly handled DSA signing. An
attacker could possibly use this issue to perform a timing side-channel
attack and recover private DSA keys. (CVE-2018-0734)
Samuel Weiser discovered that OpenSSL incorrectly handled ECDSA signing. An
attacker could possibly use this issue to perform a timing side-channel
attack and recover private ECDSA keys. This issue only affected Ubuntu
18.04 LTS and Ubuntu 18.10. (CVE-2018-0735)
Billy Bob Brumley, Cesar Pereida Garcia, Sohaib ul Hassan, Nicola Tuveri,
and Alejandro Cabrera Aldaya discovered that Simultaneous Multithreading
(SMT) architectures are vulnerable to side-channel leakage. This issue is
known as "PortSmash". An attacker could possibly use this issue to perform
a t
OSV
CVE-2018-5407: Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing att
osv·2018-11-15·CVSS 4.7
CVE-2018-5407 [MEDIUM] CVE-2018-5407: Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing att
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2018-12-06·CVSS 5.9
CVE-2018-0734 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Samuel Weiser discovered that OpenSSL incorrectly handled DSA signing. An
attacker could possibly use this issue to perform a timing side-channel
attack and recover private DSA keys. (CVE-2018-0734)
Samuel Weiser discovered that OpenSSL incorrectly handled ECDSA signing. An
attacker could possibly use this issue to perform a timing side-channel
attack and recover private ECDSA keys. This issue only affected Ubuntu
18.04 LTS and Ubuntu 18.10. (CVE-2018-0735)
Billy Bob Brumley, Cesar Pereida Garcia, Sohaib ul Hassan, Nicola Tuveri,
and Alejandro Cabrera Aldaya discovered that Simultaneous Multithreading
(SMT) architectures are vulnerable to side-channel leakage. This issue is
known as "PortSmash". An a
Red Hat
openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash)
vendor_redhat·2018-10-30·CVSS 4.7
CVE-2018-5407 [MEDIUM] CWE-200 openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash)
openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash)
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
A microprocessor side-channel vulnerability was found on SMT (e.g, Hyper-Threading) architectures. An attacker running a malicious process on the same core of the processor as the victim process can extract certain secret information.
Statement: This is a timing side-channel flaw on processors which implement SMT/Hyper-Threading architectures. It can result in leakage of secret data in applications such as OpenSSL that has secret dependent control flow at any granularity level. In order to exploit this flaw, the attacker needs to
Debian
CVE-2018-5407: openssl - Simultaneous Multi-threading (SMT) in processors can enable local users to explo...
vendor_debian·2018·CVSS 4.7
CVE-2018-5407 [MEDIUM] CVE-2018-5407: openssl - Simultaneous Multi-threading (SMT) in processors can enable local users to explo...
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
Scope: local
bookworm: resolved (fixed in 1.1.1~~pre9-1)
bullseye: resolved (fixed in 1.1.1~~pre9-1)
forky: resolved (fixed in 1.1.1~~pre9-1)
sid: resolved (fixed in 1.1.1~~pre9-1)
trixie: resolved (fixed in 1.1.1~~pre9-1)
No detection rules found.
Bugzilla
Side channel attack on ECDSA signature generation
bugzilla·2020-04-20
Side channel attack on ECDSA signature generation
Side channel attack on ECDSA signature generation
Created attachment 9141838
wnaf_trace.jpg
[filed from mail to security@ from Sohaib ul Hassan]
Hey Folks!
We are a team of security researchers from Tampere University, Finland.
We have discovered a vulnerability in ECDSA signature generation that
enables us to exfiltrate information from various side channels and
recover the private key.
# Vulnerable function
The vulnerability is found in the non-constant time ECC scalar
multiplication function ec_GFp_pt_mul_jm_wNAF @
lib/freebl/ecl/ecp_jm.cecp_jm.c. This code path is executed when
either NIST_P384 or NIST_P521 EC curve is selected. The wNAF scalar
multiplication computes EC point doubling (ec_GFp_pt_dbl_jm) at each
iteration, with a conditional branch depending on non-zero scalar
dig
Bugzilla
CVE-2018-5407 compat-openssl10: openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) [fedora-all]
bugzilla·2018-11-02·CVSS 4.7
CVE-2018-5407 [MEDIUM] CVE-2018-5407 compat-openssl10: openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) [fedora-all]
CVE-2018-5407 compat-openssl10: openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2018-5407 mingw-openssl: openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) [epel-7]
bugzilla·2018-11-02·CVSS 4.7
CVE-2018-5407 [MEDIUM] CVE-2018-5407 mingw-openssl: openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) [epel-7]
CVE-2018-5407 mingw-openssl: openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion
Bugzilla
CVE-2018-5407 mingw-openssl: openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) [fedora-all]
bugzilla·2018-11-02·CVSS 4.7
CVE-2018-5407 [MEDIUM] CVE-2018-5407 mingw-openssl: openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) [fedora-all]
CVE-2018-5407 mingw-openssl: openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOT
Bugzilla
CVE-2018-5407 openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash)
bugzilla·2018-11-02·CVSS 4.7
CVE-2018-5407 [MEDIUM] CVE-2018-5407 openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash)
CVE-2018-5407 openssl: Side-channel vulnerability on SMT/Hyper-Threading architectures (PortSmash)
A flaw was found in microprocessor execution engine sharing on SMT (e.g. Hyper-Threading) architectures. An attacker running a malicious process on the same core of the processor as the victim process, can extract certain secret information.
The reporter is able to steal an OpenSSL (<= 1.1.0h) P-384 private key from a TLS server using this new side-channel vector. It is a local attack in the sense that the malicious process must be running on the same physical core as the victim (an openSSL-powered TLS server in this case). But in general any application which branches on a secret value may be affected.
References:
https://seclists.org/oss-sec/2018/q4/123
Discussion:
Created compat-opens
arXiv
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
arxiv_fulltext·2025-02-16
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
Yuning Jiang
[email protected]
0000-0003-4791-8452
National University of Singapore
Singapore
Nay Oo
[email protected]
NCS Cyber Special Ops R&D
Singapore
Qiaoran Meng
[email protected]
National University of Singapore
Singapore
Hoon Wei Lim
[email protected]
NCS Cyber Special Ops R&D
Singapore
Biplab Sikdar
[email protected]
National University of Singapore
Singapore
Jiang et al.
## Abstract
As interconnected systems proliferate, safeguarding complex infrastructures against an escalating array of cyber threats has become an urgent challenge. The growing number of vulnerabilities, coupled with resource constraints, makes addressing every vulnerability impractical, thereby rende
arXiv
Empirical Analysis of Software Vulnerabilities Causing Timing Side Channels
arxiv_fulltext·2023-08-23
Empirical Analysis of Software Vulnerabilities Causing Timing Side Channels
Empirical Analysis of Software Vulnerabilities Causing Timing Side Channels
M. Mehdi Kholoosi12,
M. Ali Babar12,
Cemal Yilmaz3
1 School of Computer Science, CREST, The University of Adelaide, Adelaide, Australia
2 Cyber Security Cooperative Research Centre, Australia
3 Faculty of Engineering and Natural Sciences, Sabanci University, Istanbul, 34956, Turkey
Emails: [email protected], [email protected], [email protected]
## Abstract
Timing attacks are considered one of the most damaging side-channel attacks. These attacks exploit timing fluctuations caused by certain operations to disclose confidential information to an attacker. For instance, in asymmetric encryption, operations such as multiplication and division can cause time-varying execution times th
arXiv
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
arxiv_fulltext·2022-12-29
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
One Bad Apple Spoils the Barrel: Understanding the Security Risks Introduced by Third-Party Components in IoT Firmware
## Abstract
Currently, the development of IoT firmware heavily depends on third-party components (TPCs) to improve development efficiency. Nevertheless, TPCs are not secure, and the vulnerabilities in TPCs will influence the security of IoT firmware. Existing works pay less attention to the vulnerabilities caused by TPCs, and we still lack a comprehensive understanding of the security impact of TPC vulnerability against firmware. To fill in the knowledge gap, we design and implement , which leverages syntactical features and control-flow graph features to detect the TPCs in firmware, and then recognizes the corresponding vulnerabilities. Based on , we present the first l
arXiv
Investigating Black-Box Function Recognition Using Hardware Performance Counters
arxiv_fulltext·2022-11-28
Investigating Black-Box Function Recognition Using Hardware Performance Counters
Investigating Black-Box Function Recognition Using Hardware Performance Counters
Carlton Shepherd, Benjamin Semal, and Konstantinos Markantonakis
All authors are of Royal Holloway, University of London, Egham, Surrey, United Kingdom.
E-mail: [email protected].
Shepherd et al.
## Abstract
This paper presents new methods and results for recognising black-box program functions using hardware performance counters (HPC), where an investigator can invoke and measure function calls. Important use cases include analysing compiled libraries, e.g.\ static and dynamic link libraries, and trusted execution environment (TEE) applications. We develop a generic approach to classify a comprehensive set of hardware events, e.g.\ branch mis-predictions and instruction retirements, to recognise standard
http://www.securityfocus.com/bid/105897https://access.redhat.com/errata/RHSA-2019:0483https://access.redhat.com/errata/RHSA-2019:0651https://access.redhat.com/errata/RHSA-2019:0652https://access.redhat.com/errata/RHSA-2019:2125https://access.redhat.com/errata/RHSA-2019:3929https://access.redhat.com/errata/RHSA-2019:3931https://access.redhat.com/errata/RHSA-2019:3932https://access.redhat.com/errata/RHSA-2019:3933https://access.redhat.com/errata/RHSA-2019:3935https://eprint.iacr.org/2018/1060.pdfhttps://github.com/bbbrumley/portsmashhttps://lists.debian.org/debian-lts-announce/2018/11/msg00024.htmlhttps://nodejs.org/en/blog/vulnerability/november-2018-security-releases/https://security.gentoo.org/glsa/201903-10https://security.netapp.com/advisory/ntap-20181126-0001/https://support.f5.com/csp/article/K49711130?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/3840-1/https://www.debian.org/security/2018/dsa-4348https://www.debian.org/security/2018/dsa-4355https://www.exploit-db.com/exploits/45785/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttps://www.tenable.com/security/tns-2018-16https://www.tenable.com/security/tns-2018-17http://www.securityfocus.com/bid/105897https://access.redhat.com/errata/RHSA-2019:0483https://access.redhat.com/errata/RHSA-2019:0651https://access.redhat.com/errata/RHSA-2019:0652https://access.redhat.com/errata/RHSA-2019:2125https://access.redhat.com/errata/RHSA-2019:3929https://access.redhat.com/errata/RHSA-2019:3931https://access.redhat.com/errata/RHSA-2019:3932https://access.redhat.com/errata/RHSA-2019:3933https://access.redhat.com/errata/RHSA-2019:3935https://eprint.iacr.org/2018/1060.pdfhttps://github.com/bbbrumley/portsmashhttps://lists.debian.org/debian-lts-announce/2018/11/msg00024.htmlhttps://nodejs.org/en/blog/vulnerability/november-2018-security-releases/https://security.gentoo.org/glsa/201903-10https://security.netapp.com/advisory/ntap-20181126-0001/https://support.f5.com/csp/article/K49711130?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/3840-1/https://www.debian.org/security/2018/dsa-4348https://www.debian.org/security/2018/dsa-4355https://www.exploit-db.com/exploits/45785/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttps://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttps://www.tenable.com/security/tns-2018-16https://www.tenable.com/security/tns-2018-17
2018-11-15
Published