Security Advisory

CVE-2020-8935

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-12-15 14:55:32
Last updated 2024-08-04 10:12:11
Assigner Google
CVSS score 5.3
State PUBLISHED

Description

An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allow an attacker to make an Ecall_restore function call to reallocate untrusted code and overwrite sections of the Enclave memory address. We recommend updating your library.