CVE-2020-8935

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
15/12/2020
Last modified:
21/07/2021

Description

An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allow an attacker to make an Ecall_restore function call to reallocate untrusted code and overwrite sections of the Enclave memory address. We recommend updating your library.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:google:asylo:*:*:*:*:*:*:*:* 0.6.0 (including)