| |
Vulnerability CVE-2020-8938
Published: 2020-12-15
Description: |
An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allows an attacker to make a host call to FromkLinuxSockAddr with attacker controlled content and size of klinux_addr which allows an attacker to write memory values from within the enclave. We recommend upgrading past commit a37fb6a0e7daf30134dbbf357c9a518a1026aa02 |
Type:
CWE-787
CVSS2 => (AV:L/AC:L/Au:N/C:N/I:P/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
2.1/10 |
2.9/10 |
3.9/10 |
Exploit range |
Attack complexity |
Authentication |
Local |
Low |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
None |
Partial |
None |
References: |
https://github.com/google/asylo/commit/bda9772e7872b0d2b9bee32930cf7a4983837b39
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|