Vulnerability Description
An issue was discovered in UC Berkeley RISE Opaque before 2018-12-01. There is no boundary check on ocall_malloc. The return value could be a pointer to enclave memory. It could cause an arbitrary enclave memory write.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ucbrise | Opaque | < 2018-12-01 |
Related Weaknesses (CWE)
References
- https://github.com/ucbrise/opaque/commit/5ddda15d89f5ac82f4416208c5319ace4aecdc3PatchThird Party Advisory
- https://github.com/ucbrise/opaque/issues/66ExploitPatchThird Party Advisory
- https://github.com/ucbrise/opaque/commit/5ddda15d89f5ac82f4416208c5319ace4aecdc3PatchThird Party Advisory
- https://github.com/ucbrise/opaque/issues/66ExploitPatchThird Party Advisory
FAQ
What is CVE-2018-20742?
CVE-2018-20742 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in UC Berkeley RISE Opaque before 2018-12-01. There is no boundary check on ocall_malloc. The return value could be a pointer to enclave memory. It could cause an arbitrary enc...
How severe is CVE-2018-20742?
CVE-2018-20742 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-20742?
Check the references section above for vendor advisories and patch information. Affected products include: Ucbrise Opaque.