PT-2020-20379 · Google · Asylo

Kang Li

+3

·

Published

2020-12-15

·

Updated

2020-12-17

·

CVE-2020-8941

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Asylo versions up to 0.6.0
Description An arbitrary memory read issue allows an untrusted attacker to make a call to enc untrusted inet pton using an attacker-controlled klinux addr buffer parameter. The parameter size is unchecked, allowing the attacker to read memory locations outside of the intended buffer size, including memory addresses within the secure enclave.
Recommendations For Asylo versions up to 0.6.0, upgrade past commit 8fed5e334131abaf9c5e17307642fbf6ce4a57ec to resolve the issue. As a temporary workaround, consider restricting access to the enc untrusted inet pton function and the klinux addr buffer parameter to minimize the risk of exploitation.

Fix

Out of bounds Read

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8941

Affected Products

Asylo