CVE-2020-8937
Summary
| CVE | CVE-2020-8937 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-15 15:15:00 UTC |
| Updated | 2020-12-17 14:45:00 UTC |
| Description | An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allows an attacker to make a host call to enc_untrusted_create_wait_queue that uses a pointer queue that relies on UntrustedLocalMemcpy, which fails to validate where the pointer is located. This allows an attacker to write memory values from within the enclave. We recommend upgrading past commit a37fb6a0e7daf30134dbbf357c9a518a1026aa02 |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Check untrusted queue is in outside enclave · google/asylo@a37fb6a · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Qinkun Bao (Baidu Security)
LEGACY: Zhaofeng Chen (Baidu Security)
LEGACY: Mingshen Sun (Baidu Security)
LEGACY: Kang Li (Baidu Security)
There are currently no legacy QID mappings associated with this CVE.