CVE-2005-0109 describes a timing attack vulnerability in Hyper-Threading technology, affecting FreeBSD and other operating systems on Intel Pentium processors. A local attacker can exploit this to create covert channels, monitor other threads, and extract sensitive information like cryptographic keys by analyzing memory cache misses. With a CVSS score of 5.6 (Medium), this vulnerability requires local access and high attack complexity but can lead to high confidentiality impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.5.1CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:1.1.5.1:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:2.0:*:*:*:*:*:*:* | ||
2.0.5CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:2.0.5:*:*:*:*:*:*:* | ||
2.1.0CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:2.1.0:*:*:*:*:*:*:* | ||
2.1.5CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:2.1.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.