Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to Information Exposure. Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka "straight-line speculation."
Remediation
There is no fixed version for gcc-8
.
References
CVSS Score
5.5
medium severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredLow
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityNone
-
AvailabilityNone
- CVE
- CVE-2020-13844
- CWE
- CWE-200
- Snyk ID
- SNYK-UBUNTU1804-GCC8-572149
- Disclosed
- 08 Jun, 2020
- Published
- 12 Jun, 2020