Out of Bounds read in Asylo
Vulnerability Description
An out of bounds read on the enc_untrusted_inet_ntop function allows an attack to extend the result size that is used by memcpy() to read memory from within the enclave heap. We recommend upgrading past commit 6ff3b77ffe110a33a2f93848a6333f33616f02c4
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-8939
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Qinkun Bao (Baidu Security)
- Zhaofeng Chen (Baidu Security)
- Mingshen Sun (Baidu Security)
- Kang Li (Baidu Security)
More from Google LLC
View All →Affected Vendor
Google LLC
View all reports →