PT-2020-20379 · Google · Asylo
Kang Li
+3
·
Published
2020-12-15
·
Updated
2020-12-17
·
CVE-2020-8941
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Asylo versions up to 0.6.0
Description
An arbitrary memory read issue allows an untrusted attacker to make a call to
enc untrusted inet pton using an attacker-controlled klinux addr buffer parameter. The parameter size is unchecked, allowing the attacker to read memory locations outside of the intended buffer size, including memory addresses within the secure enclave.Recommendations
For Asylo versions up to 0.6.0, upgrade past commit 8fed5e334131abaf9c5e17307642fbf6ce4a57ec to resolve the issue. As a temporary workaround, consider restricting access to the
enc untrusted inet pton function and the klinux addr buffer parameter to minimize the risk of exploitation.Fix
Out of bounds Read
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Asylo