CVE-2018-20742

HIGH

UC Berkeley RISE Opaque < 2018-12-01 - Out-of-bounds Write via ocall_malloc

Title source: llm
STIX 2.1

Description

An issue was discovered in UC Berkeley RISE Opaque before 2018-12-01. There is no boundary check on ocall_malloc. The return value could be a pointer to enclave memory. It could cause an arbitrary enclave memory write.

References (2)

Core 2
Core References
Exploit, Patch, Third Party Advisory x_refsource_misc
https://github.com/ucbrise/opaque/issues/66

Scores

CVSS v3 7.5
EPSS 0.0138
EPSS Percentile 68.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-787
Status published
Products (1)
ucbrise/opaque < 2018-12-01
Published Jan 24, 2019
Tracked Since Feb 18, 2026