#VU14518 Information disclosure in OpenBSD


Published: 2018-08-23

Vulnerability identifier: #VU14518

Vulnerability risk: Low

CVSSv3.1: 3 [CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: N/A

CWE-ID: CWE-200

Exploitation vector: Local network

Exploit availability: No

Vulnerable software:
OpenBSD
Operating systems & Components / Operating system

Vendor: OpenBSD

Description

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to the Intel L1TF vulnerability that allows a vmm guest to read host memory. A local privileged user on virtual machine can gain access to data stored in memory on the host system.



Mitigation
Install update from vendor's website.

Vulnerable software versions

OpenBSD: 6.2 - 6.3


External links
http://ftp.openbsd.org/pub/OpenBSD/patches/6.3/common/018_vmml1tf.patch.sig


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability