VirtualBox

Changeset 57609 in vbox for trunk


Ignore:
Timestamp:
Sep 3, 2015 11:58:45 AM (9 years ago)
Author:
vboxsync
Message:

manual: rephrased the comment.

Location:
trunk/doc/manual/en_US
Files:
2 edited

Legend:

Unmodified
Added
Removed
  • trunk/doc/manual/en_US/user_GuestAdditions.xml

    r57607 r57609  
    18571857        linkend="metrics" /> for information on how to query metrics.</para>
    18581858
    1859       <note><para>Enabling Page Fusion might improve the chances for malicious
    1860        guests to successfully attack other VMs running on the same host using
    1861        side-channel attacks, see <xref linkend="pot-insecure"/>.</para></note>
     1859      <note><para>Enabling Page Fusion might indirectly increase the chances
     1860      for malicious guests to successfully attack other VMs running on the
     1861      same host, see <xref linkend="pot-insecure"/>.</para></note>
    18621862    </sect2>
    18631863  </sect1>
  • trunk/doc/manual/en_US/user_Security.xml

    r57607 r57609  
    330330        <listitem>
    331331          <para>When Page Fusion (see <xref linkend="guestadd-pagefusion"/>)
    332           is enabled, a malicious guest doing a side-channel attack could be
    333           able to determine the address space layout of another guest running
    334           on the same host. This would improve the chances of the malicious guest
    335           to take advantage of other attack vectors he might have against the
    336           target VM. To prevent potential malcious guest process from doing
    337           such side-channel attacks, Page Fusion should be disabled.</para>
     332          is enabled, it is possible that a side-channel opens up that allows
     333          a malicious guest to determin the address space layout (i.e. where
     334          DLLs are typically loaded) of one other VM running on the same host.
     335          This information leak in it self is harmless, however the malicious
     336          guest may use it to optimize attack against that VM via unrelated
     337          attack vectors.  It is recommended to only enable Page Fusion if you
     338          do not think this is a concern in your setup.</para>
    338339        </listitem>
    339340
Note: See TracChangeset for help on using the changeset viewer.

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette