PT-2020-20361 · Google · Asylo

Kang Li

+3

·

Published

2020-08-12

·

Updated

2020-08-13

·

CVE-2020-8904

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Asylo versions prior to 0.6.0
Description The issue is related to an arbitrary memory overwrite in the trusted memory of Asylo. It occurs because the ecall restore function does not properly validate the range of the output len pointer, allowing an attacker to manipulate the tmp output len value and write to any location in the trusted memory.
Recommendations Update Asylo to version 0.6.0 or later.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8904

Affected Products

Asylo