Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h23p-6vvh-q288

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in SKALE sgxwallet 1.58.3. sgx_disp_ippsAES_GCMEncrypt allows an out-of-bounds write, resulting in a segfault and compromised enclave. This issue describes a buffer overflow, which was resolved prior to v1.77.0 and not reproducible in latest sgxwallet v1.77.0

An issue was discovered in SKALE sgxwallet 1.58.3. sgx_disp_ippsAES_GCMEncrypt allows an out-of-bounds write, resulting in a segfault and compromised enclave. This issue describes a buffer overflow, which was resolved prior to v1.77.0 and not reproducible in latest sgxwallet v1.77.0

EPSS

Процентиль: 61%
0.00408
Низкий

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

An issue was discovered in SKALE sgxwallet 1.58.3. sgx_disp_ippsAES_GCMEncrypt allows an out-of-bounds write, resulting in a segfault and compromised enclave. This issue describes a buffer overflow, which was resolved prior to v1.77.0 and not reproducible in latest sgxwallet v1.77.0

CVSS3: 7.5
fstec
больше 4 лет назад

Уязвимость функции sgx_disp_ippsAES_GCMEncrypt кошелька для криптовалют sgxwallet, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 61%
0.00408
Низкий

Дефекты

CWE-787