Secunia CSI 5.0
Products
Solutions
Customers
Partner
Resources
Company
Careers
Community

CVE Reference: CVE-2006-1056

NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-1056

Description:
The Linux kernel before 2.6.16.9 and the FreeBSD kernel, when running on AMD64 and other 7th and 8th generation AuthenticAMD processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one process to determine portions of the state of floating point instructions of other processes, which can be leveraged to obtain sensitive information such as cryptographic keys. NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processers in a security-relevant fashion that was not addressed by the kernels.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/25871

UBUNTU
  http://www.ubuntu.com/usn/usn-302-1

SUSE
  http://www.novell.com/linux/security/advisories/2006-05-31.html

ST
  1015966

SAID
  Secunia Advisory: SA22875
  Secunia Advisory: SA22876
  Secunia Advisory: SA19735
  Secunia Advisory: SA22417
  Secunia Advisory: SA21983
  Secunia Advisory: SA20398
  Secunia Advisory: SA21465
  Secunia Advisory: SA21136
  Secunia Advisory: SA21035
  Secunia Advisory: SA20914
  Secunia Advisory: SA20716
  Secunia Advisory: SA20671
  Secunia Advisory: SA19715
  Secunia Advisory: SA19724

REDHAT
  http://www.redhat.com/support/errata/RHSA-2006-0575.html
  http://www.redhat.com/support/errata/RHSA-2006-0437.html
  http://www.redhat.com/support/errata/RHSA-2006-0579.html

OVAL
  http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:9995

OSVDB
  24746
  24807

MLIST
  http://marc.theaimsgroup.com/?l=linux-kernel&m=114548768214478&w=2

MISC
  http://security.freebsd.org/advisories/FreeBSD-SA-06:14-amd.txt

FREEBSD

FEDORA
  http://lwn.net/Alerts/180820/

DEBIAN
  http://www.debian.org/security/2006/dsa-1103
  http://www.debian.org/security/2006/dsa-1097

CONFIRM
  http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.9
  http://www.vmware.com/download/esx/esx-254-200610-patch.html
  http://support.avaya.com/elmodocs2/security/ASA-2006-180.htm
  http://support.avaya.com/elmodocs2/security/ASA-2006-200.htm
  http://kb.vmware.com/kb/2533126
  http://www.vmware.com/download/esx/esx-213-200610-patch.html

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/451421/100/0/threaded
  http://www.securityfocus.com/archive/1/archive/1/451417/100/200/threaded
  http://www.securityfocus.com/archive/1/archive/1/451419/100/200/threaded
  http://www.securityfocus.com/archive/1/archive/1/451404/100/0/threaded

BID
  17600


Return to the previous page.


 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Factsheets
Reports & Papers
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2012 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability