Groups | Search | Server Info | Keyboard shortcuts | Login | Register


Groups > linux.debian.security > #5597

Re: Intel Microcode updates

Path csiph.com!2.eu.feeder.erje.net!3.eu.feeder.erje.net!feeder.erje.net!weretis.net!feeder7.news.weretis.net!news.mixmin.net!aioe.org!bofh.it!news.nic.it!robomod
From Andrew McGlashan <andrew.mcglashan@affinityvision.com.au>
Newsgroups linux.debian.security
Subject Re: Intel Microcode updates
Date Tue, 11 Jun 2019 21:20:01 +0200
Message-ID <y7Utj-64f-5@gated-at.bofh.it> (permalink)
References <y7jN8-18n-3@gated-at.bofh.it> <y7Eyd-52j-1@gated-at.bofh.it> <y7Srw-4S3-13@gated-at.bofh.it> <y7SBb-4VG-1@gated-at.bofh.it> <y7UjD-60r-9@gated-at.bofh.it>
X-Original-To debian-security@lists.debian.org
X-Mailbox-Line From debian-security-request@lists.debian.org Tue Jun 11 19:10:09 2019
Old-Return-Path <andrew.mcglashan@affinityvision.com.au>
X-Amavis-Spam-Status No, score=-12.18 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FVGT_m_MULTI_ODD=0.02, LDO_WHITELIST=-5, PGPSIGNATURE=-5] autolearn=ham autolearn_force=no
Dkim-Signature v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=affinityvision.com.au; s=2018061201; h=Subject:Content-Transfer-Encoding: Content-Type:In-Reply-To:MIME-Version:Date:Message-ID:From:References:To: Sender:Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help: List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=AeCOOSvXgSy3vB+fLhsGnz3dx52PAgSp8HiyXRiQtSk=; b=M0LcUDBfBxKUWhRa8IQzGbZqZi US1GdHGc0tVNtwjx+fe0JriPEKUlQPCeDDFbHSACWwtcysMpBU9f/IILSNiRPvCfTIOVjKDRltySo FLF1Hu4+w6uRxBDMVGojMywg9H4tEPjFCgaoL1u/WBFH6BovZQwnhFmwkUE+qRi4kY90gE8DUwZE4 qrNIoYPbbMtkFYQqR28wAyav20kyOi23ryzK6wuMvA00KaP6slihFhKclIvLZfqOeNgE6rVM1+se6 N5pIoEDcP64LGZNwdg9JLByriq5kKRCixydI/fV+JyvUhMVIiX4Rpw0mEiNUALee0xf1ukO6MLVmD Q0yKQ4nw==;
Openpgp preference=signencrypt
Autocrypt addr=andrew.mcglashan@affinityvision.com.au; prefer-encrypt=mutual; keydata= mQMuBE+HAUgRCACcvrI68WkPlSiUwdwqTc+ppWhVcUfFXQK8eud6/oKIzcnxG7PvaLWZZEWK ptBygx/btrjHZ6SVvUqxiUjhHPRk6/enEpgbXyXKu2t0hy7ebi6V0vw8VYTxU8Fvkp1t4MSq /G23d+Gc0Peytlhq1a2TrGE4WtRChZTyUTe2wfTj8p5A3L3rTOHlQPbPeboYUDcQastHlvxB 4R5dA0hyTroIZys8MoaMiasZ9EMIW/eCz6Wt6wKuxpF7rk1XvE1ZBigf9h8QW+ISUsvU6igc Zq5rfXNB9bHXiQaNVeYthBrI04vBx6SoYi+a+MaQGGLmIAjTGMhIN6yU30zyS+HcAhZnAQDg ViitrOq9z4LdIVc32c8pLBWQuhZWfxfxdyjz35updQf/fTQyX2SWN8aryODJ75f8u0TOMMQU YKvkNFmyML4ESF59N7BY+aWWxLMvcMWm881njVeX+u9f/q+12tW4hr4wJC2x4ath8nw3V6B0 IdEWrYZIq/xgpLKeIGMpVMfu/S/E6KyWQ+egQiteAUYEm3069CTtXE+jmBELlbpCBQjctse1 qfTKiEusfd5a1KvwHzaDNidsSlpenMLIKVdi1WOnXCskOVmbr3xaWkJLy/tgoqK9DXiIIMaw 0F5zcfIi+y5YjPacK5fxjnXQk1k59vJGX25YDqvRBCbPMvOvyYmcbH/RrD98jeM70INAH89q TQzOdBlTI8/IXfvm9OBd/JtRMgf+PIKRdxEoOes+gA4Oig8SM34RU2HxRMLnth+yCVmLKbdY xC5fdkAgGVW7XhPhMcZFGaSAkx7hhe7UfepGclcHesjmRzIIwlB4TYsy22Q4RoTaDlx4Xhgi 7Py1Xk7H+G0QpKvEOK5yY9bYrwKMcK1UgbTr35S4V0i0SEZwN3pn3qQnKy2JWJcGBGZ16R1O CpGu0+GqUFgX2uSHp37VlKCFvADdyhMXl4Bm5hLo16BBE1HU+IBry1/+/QndmCR1mlzEVrE2 ATIMn/OxqCWMXv+Hplg3buWfSDsRyk6z1ppB0QctYlIltQTB7fiqmnCpKBIPs7giIXLrzcnJ K8nZzsfNN7Q5QW5kcmV3IE1jR2xhc2hhbiA8YW5kcmV3Lm1jZ2xhc2hhbkBhZmZpbml0eXZp c2lvbi5jb20uYXU+iH0EExEIACUCGwMGCwkIBwMCBhUIAgkKCwQWAgMBAh4BAheABQJPhxxz AhkBAAoJEKgWa8u37+L7qa4BANGmMQZGJRsy7EG6XzaHmegHUsZSH1EfLNRQGe19ww2rAQCp CoVAiEJhU07rRqothFQFvHOOsW/nqZV9Bf/GowPOH7kCDQRPhwFIEAgA07aMf8Ko18UQNg85 BmXdDLf9mFmyeVO+72skn+9GVb8AeqWuGn8FCxTawu2HKfo78RBo87HhIRNlIaPuqOVBiVOu XNqtEbOlyceLpa2PXml2ZBwLPlSLjy5EliR386aYKH9zfwVFlTeYK7gEYqsxF96KluhlpGmV d6p/ZOifY3+lYbDI/3XAbMdV7UqAQXdwA2OTrR2t2YMwIey0FbV1n/K6RJwuWahi16fLYvUC J87oeBB+bBX0Vrulx7BLf+fXZ8g848etS0177yyqG2tk3ZqESjt9QG/938QC2VH52HT9eqyN F9I7QY2akVrX+Iw1NfqlyIFlRyMijUGZ4dW5/wADBQgAx8RcstB6wgVjlqhWFRfyvtzBqcND W6oZmJPjMCP9u3lJt/0imXxyCQQjkRW/UytiJ5AOOrS480Xajx3UbMAaWR8kSL32z2T0Ct4Y Z0dMXKO53bUpiprUMgcnKa8D2dWdcsZf/FoEN1nack6taejZ0GD7bBgNIPo+s+DO8jKLDTWI qlb0mp/p2OVz5Sar/kseoa/YnF7+P5dSiUyxuqELSCEKeyoE/4F1GsYx+3d2WVzmfaoSPEkI b6bfilKoaM3m9fOUHa4RGUTlMdSoTKU1Jq/55YImsRdwb9s+YIypm+4HvZyrlthdtBhLJDv4 kTcHitFjZvkeOSPcBVmNfYLZJYhhBBgRCAAJBQJPhwFIAhsMAAoJEKgWa8u37+L78UQA/3LM bAxXz0lUDkdkb+A3oTy5a6PhGubYyr1o9IVZMm6iAQDcAiIaJMIbjSynVu+Er2fJrDgnByoI Y81Rl2gGWKMEJg==
User-Agent Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.7.0
MIME-Version 1.0
Content-Type text/plain; charset=utf-8
Content-Language en-US
Content-Transfer-Encoding 7bit
X-Sa-Exim-Connect-IP 192.168.0.40
X-Sa-Exim-Mail-From andrew.mcglashan@affinityvision.com.au
X-Sa-Exim-Version 4.2.1 (built Tue, 02 Aug 2016 21:08:31 +0000)
X-Sa-Exim-Scanned Yes (on mail.affinityvision.com.au)
X-Mailing-List <debian-security@lists.debian.org> archive/latest/28708
List-ID <debian-security.lists.debian.org>
List-URL <https://lists.debian.org/debian-security/>
List-Archive https://lists.debian.org/msgid-search/990ae84a-a151-b624-6f7d-08eab5366bfb@affinityvision.com.au
Approved robomod@news.nic.it
Lines 29
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Date Wed, 12 Jun 2019 05:09:49 +1000
X-Original-Message-ID <990ae84a-a151-b624-6f7d-08eab5366bfb@affinityvision.com.au>
X-Original-References <3261648.SxaLSeNWXX@xev> <20190611021914.eiq2ins57wlj3x6l@khazad-dum.debian.net> <08981663-1152-cbbd-7ca9-c3a5c4db846c@affinityvision.com.au> <20190611171632.wjp4a43bvi6xol6e@layer-acht.org> <105b058c-95d6-6792-6b05-5f7ee8e64d3a@affinityvision.com.au>
Xref csiph.com linux.debian.security:5597

Show key headers only | View raw


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Hi,

> On 12/6/19 3:16 am, Holger Levsen wrote:
>> On Wed, Jun 12, 2019 at 03:05:13AM +1000, Andrew McGlashan
>> wrote:
>>> Exploiting the flaws needs malicious code to be running on your
>>>  box.  If you are in total control over all VMs and processes
>>> on the box, then you should be good.
> 
>> do you use a webbrowser with javascript enabled?
> 
> Good point, yes that is another risk.

Actually though, if you update your browser to lessen the granularity
of time that the exploits require, it might not be an issue.  So,
don't run an out of date browser....  is that enough?

Cheers
A.
-----BEGIN PGP SIGNATURE-----

iHUEAREIAB0WIQTJAoMHtC6YydLfjUOoFmvLt+/i+wUCXP/8eAAKCRCoFmvLt+/i
+2AsAP4knXw4eLsVrlYm/CwuWJrhGC8FRVj4Uc09H0mR2ZDlhwD/RI/FDdLYiO9t
nNNga1FHGhCMj7v/rzJcZ/8iGrNrmqI=
=/5dj
-----END PGP SIGNATURE-----

Back to linux.debian.security | Previous | NextPrevious in thread | Next in thread | Find similar


Thread

Intel Microcode updates Russell Coker <russell@coker.com.au> - 2019-06-10 06:10 +0200
  Re: Intel Microcode updates Michael Stone <mstone@debian.org> - 2019-06-10 13:20 +0200
    Re: Intel Microcode updates Davide Prina <davide.prina@gmail.com> - 2019-06-10 19:50 +0200
      Re: Intel Microcode updates Michael Stone <mstone@debian.org> - 2019-06-10 20:40 +0200
        Re: Intel Microcode updates Davide Prina <davide.prina@gmail.com> - 2019-06-11 20:10 +0200
          Re: Intel Microcode updates Michael Stone <mstone@debian.org> - 2019-06-11 22:00 +0200
    Re: Intel Microcode updates Russell Coker <russell@coker.com.au> - 2019-06-11 14:00 +0200
  Re: Intel Microcode updates Henrique de Moraes Holschuh <hmh@debian.org> - 2019-06-11 04:20 +0200
    Re: Intel Microcode updates Russell Coker <russell@coker.com.au> - 2019-06-11 14:00 +0200
      Re: Intel Microcode updates Moritz Mühlenhoff <jmm@inutil.org> - 2019-06-11 14:30 +0200
        Re: Intel Microcode updates Henrique de Moraes Holschuh <hmh@debian.org> - 2019-06-12 17:00 +0200
          Re: Intel Microcode updates Elmar Stellnberger <estellnb@gmail.com> - 2019-06-18 13:00 +0200
            Re: Intel Microcode updates Henrique de Moraes Holschuh <hmh@debian.org> - 2019-06-23 22:30 +0200
              Re: Intel Microcode updates Elmar Stellnberger <estellnb@gmail.com> - 2019-06-23 22:40 +0200
                Re: Intel Microcode updates Henrique de Moraes Holschuh <hmh@debian.org> - 2019-06-24 04:10 +0200
              Re: Intel Microcode updates Davide Prina <davide.prina@gmail.com> - 2019-06-24 19:40 +0200
          Re: Intel Microcode updates Elmar Stellnberger <estellnb@gmail.com> - 2019-06-18 22:10 +0200
          Re: Intel Microcode updates Elmar Stellnberger <estellnb@gmail.com> - 2019-06-22 14:30 +0200
    Re: Intel Microcode updates Andrew McGlashan <andrew.mcglashan@affinityvision.com.au> - 2019-06-11 19:10 +0200
      Re: Intel Microcode updates Holger Levsen <holger@layer-acht.org> - 2019-06-11 19:20 +0200
        Re: Intel Microcode updates Andrew McGlashan <andrew.mcglashan@affinityvision.com.au> - 2019-06-11 21:10 +0200
          Re: Intel Microcode updates Andrew McGlashan <andrew.mcglashan@affinityvision.com.au> - 2019-06-11 21:20 +0200
            Re: Intel Microcode updates Elmar Stellnberger <estellnb@gmail.com> - 2019-06-18 11:20 +0200
              Re: Intel Microcode updates Andrew McGlashan <andrew.mcglashan@affinityvision.com.au> - 2019-06-18 20:30 +0200
                Re: Intel Microcode updates Rob van der Putten <rob@sput.nl> - 2019-06-20 14:40 +0200
            Re: Intel Microcode updates Elmar Stellnberger <estellnb@gmail.com> - 2019-06-18 22:10 +0200
            Re: Intel Microcode updates Elmar Stellnberger <estellnb@gmail.com> - 2019-06-22 14:30 +0200
    Re: Intel Microcode updates Davide Prina <davide.prina@gmail.com> - 2019-06-23 10:00 +0200
      Re: Intel Microcode updates Lou Poppler <LouPoppler@cableone.net> - 2019-06-24 02:20 +0200
        Re: Intel Microcode updates Davide Prina <davide.prina@gmail.com> - 2019-06-24 20:00 +0200

csiph-web