CVE-2005-0109: Medium severity FreeBSD FreeBSD vulnerability

Published Mar 5, 2005
·
Updated

Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.

Affected Software

122 affected components
FreeBSD FreeBSD=1.1.5.1
FreeBSD FreeBSD=2.0
FreeBSD FreeBSD=2.0.5
FreeBSD FreeBSD=2.1.0
FreeBSD FreeBSD=2.1.5
FreeBSD FreeBSD=2.1.6
FreeBSD FreeBSD=2.1.6.1
FreeBSD FreeBSD=2.1.7.1
FreeBSD FreeBSD=2.2
FreeBSD FreeBSD=2.2.2
FreeBSD FreeBSD=2.2.3
FreeBSD FreeBSD=2.2.4
FreeBSD FreeBSD=2.2.5
FreeBSD FreeBSD=2.2.6
FreeBSD FreeBSD=2.2.8
FreeBSD FreeBSD=3.0
FreeBSD FreeBSD=3.0-releng
FreeBSD FreeBSD=3.1
FreeBSD FreeBSD=3.2
FreeBSD FreeBSD=3.3
FreeBSD FreeBSD=3.4
FreeBSD FreeBSD=3.5
FreeBSD FreeBSD=3.5-stable
FreeBSD FreeBSD=3.5.1
FreeBSD FreeBSD=3.5.1-release
FreeBSD FreeBSD=3.5.1-stable
FreeBSD FreeBSD=4.0
FreeBSD FreeBSD=4.0-alpha
FreeBSD FreeBSD=4.0-releng
FreeBSD FreeBSD=4.1
FreeBSD FreeBSD=4.1.1
FreeBSD FreeBSD=4.1.1-release
FreeBSD FreeBSD=4.1.1-stable
FreeBSD FreeBSD=4.2
FreeBSD FreeBSD=4.2-stable
FreeBSD FreeBSD=4.3
FreeBSD FreeBSD=4.3-release
FreeBSD FreeBSD=4.3-release_p38
FreeBSD FreeBSD=4.3-releng
FreeBSD FreeBSD=4.3-stable
FreeBSD FreeBSD=4.4
FreeBSD FreeBSD=4.4-release_p42
FreeBSD FreeBSD=4.4-releng
FreeBSD FreeBSD=4.4-stable
FreeBSD FreeBSD=4.5
FreeBSD FreeBSD=4.5-release
FreeBSD FreeBSD=4.5-release_p32
FreeBSD FreeBSD=4.5-releng
FreeBSD FreeBSD=4.5-stable
FreeBSD FreeBSD=4.6
FreeBSD FreeBSD=4.6-release
FreeBSD FreeBSD=4.6-release_p20
FreeBSD FreeBSD=4.6-releng
FreeBSD FreeBSD=4.6-stable
FreeBSD FreeBSD=4.6.2
FreeBSD FreeBSD=4.7
FreeBSD FreeBSD=4.7-release
FreeBSD FreeBSD=4.7-release_p17
FreeBSD FreeBSD=4.7-releng
FreeBSD FreeBSD=4.7-stable
FreeBSD FreeBSD=4.8
FreeBSD FreeBSD=4.8-pre-release
FreeBSD FreeBSD=4.8-release_p6
FreeBSD FreeBSD=4.8-releng
FreeBSD FreeBSD=4.9
FreeBSD FreeBSD=4.9-pre-release
FreeBSD FreeBSD=4.9-releng
FreeBSD FreeBSD=4.10
FreeBSD FreeBSD=4.10-release
FreeBSD FreeBSD=4.10-release_p8
FreeBSD FreeBSD=4.10-releng
FreeBSD FreeBSD=4.11-release_p3
FreeBSD FreeBSD=4.11-releng
FreeBSD FreeBSD=4.11-stable
FreeBSD FreeBSD=5.0
FreeBSD FreeBSD=5.0-alpha
FreeBSD FreeBSD=5.0-release_p14
FreeBSD FreeBSD=5.0-releng
FreeBSD FreeBSD=5.1
FreeBSD FreeBSD=5.1-alpha
FreeBSD FreeBSD=5.1-release
FreeBSD FreeBSD=5.1-release_p5
FreeBSD FreeBSD=5.1-releng
FreeBSD FreeBSD=5.2
FreeBSD FreeBSD=5.2.1-release
FreeBSD FreeBSD=5.2.1-releng
FreeBSD FreeBSD=5.3
FreeBSD FreeBSD=5.3-release
FreeBSD FreeBSD=5.3-releng
FreeBSD FreeBSD=5.3-stable
FreeBSD FreeBSD=5.4-pre-release
FreeBSD FreeBSD=5.4-release
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=2.1
redhat Enterprise Linux=3.0
redhat Enterprise Linux=3.0
redhat Enterprise Linux=3.0
redhat Enterprise Linux=4.0
redhat Enterprise Linux=4.0
redhat Enterprise Linux=4.0
redhat Enterprise Linux Desktop=3.0
redhat Enterprise Linux Desktop=4.0
redhat Fedora Core=core_3.0
SCO OpenServer=5.0.7
SCO UnixWare=7.1.3
SCO UnixWare=7.1.3_up
SCO UnixWare=7.1.4
Sun Solaris=7.0
Sun Solaris=8.0
Sun Solaris=9.0
Sun Solaris=9.0-x86_update_2
Sun Solaris=10.0
Ubuntu Ubuntu Linux=4.1
Ubuntu Ubuntu Linux=4.1
Ubuntu Ubuntu Linux=5.04
Ubuntu Ubuntu Linux=5.04
Ubuntu Ubuntu Linux=5.04
FreeBSD FreeBSD=5.4-release

Event History

Mar 5, 2005
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Mar 8, 2005
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2005-0109?

CVE-2005-0109 has a severity rating that indicates a vulnerability allowing local users to exploit hyper-threading to access sensitive information.

2

How do I fix CVE-2005-0109?

To mitigate CVE-2005-0109, it is recommended to disable hyper-threading in the BIOS settings or apply relevant patches provided by your operating system vendor.

3

What systems are affected by CVE-2005-0109?

CVE-2005-0109 affects various versions of FreeBSD and Red Hat Enterprise Linux among others.

4

What risks does CVE-2005-0109 introduce?

CVE-2005-0109 allows attackers to create covert channels, monitor thread execution, and potentially obtain sensitive information like cryptographic keys.

5

Is CVE-2005-0109 a remote or local vulnerability?

CVE-2005-0109 is classified as a local vulnerability, requiring access to the affected system to exploit.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203