UBUNTU-CVE-2017-5754
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-5754
UBUNTU-CVE-2017-5754
Summary:
Details: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
References: https://ubuntu.com/security/CVE-2017-5754, https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SpectreAndMeltdown, https://github.com/IAIK/KAISER, https://gruss.cc/files/kaiser.pdf, https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html, https://googleprojectzero.blogspot.co.uk/2018/01/reading-privileged-memory-with-side.html, https://meltdownattack.com/, https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00088&languageid=en-fr, http://www.amd.com/en/corporate/speculative-execution, https://developer.arm.com/support/security-update, https://ubuntu.com/security/notices/USN-3516-1, https://ubuntu.com/security/notices/USN-3522-1, https://ubuntu.com/security/notices/USN-3522-2, https://ubuntu.com/security/notices/USN-3523-1, https://ubuntu.com/security/notices/USN-3524-1, https://ubuntu.com/security/notices/USN-3524-2, https://ubuntu.com/security/notices/USN-3525-1, https://ubuntu.com/security/notices/USN-3523-2, https://ubuntu.com/security/notices/USN-3540-2, https://ubuntu.com/security/notices/USN-3540-1, https://ubuntu.com/security/notices/USN-3541-1, https://ubuntu.com/security/notices/USN-3541-2, https://ubuntu.com/security/notices/USN-3583-1, https://ubuntu.com/security/notices/USN-3597-1, https://ubuntu.com/security/notices/USN-3597-2, https://www.cve.org/CVERecord?id=CVE-2017-5754
Affected packages
Package
Name: firefox
Purl: pkg:deb/ubuntu/firefox?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
