Floating point information leak in the context switch code for...
Vulnerability Description
Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-0565
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/20163
- http://archives.neohapsis.com/archives/linux/owl/2004-q2/0038.html
- http://www.debian.org/security/2006/dsa-1082
- http://www.debian.org/security/2006/dsa-1070
- http://secunia.com/advisories/20162
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10714
- http://www.debian.org/security/2006/dsa-1067
- http://www.debian.org/security/2006/dsa-1069
- http://www.securityfocus.com/bid/10687
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=124734
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:066
- http://secunia.com/advisories/20202
- http://www.redhat.com/support/errata/RHSA-2004-504.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16644
- http://secunia.com/advisories/20338
More from mandrakesoft
View All →Affected Vendor
mandrakesoft
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.