First published: Mon Mar 19 2018(Updated: )
Edger8r tool in the Intel SGX SDK before version 2.1.2 (Linux) and 1.9.6 (Windows) may generate code that is susceptible to a side channel potentially allowing a local user to access unauthorized information.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel SGX SDK | <1.9.6 | |
Microsoft Windows | ||
Intel SGX SDK | <2.1.2 | |
Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of the Edger8r tool in the Intel SGX SDK is CVE-2018-3626.
CVE-2018-3626 has a severity rating of medium (4.7).
The Intel SGX SDK versions up to and excluding 2.1.2 (Linux) and 1.9.6 (Windows) are affected by CVE-2018-3626.
You can find more information about CVE-2018-3626 at the following references: [1] http://www.securityfocus.com/bid/103479 [2] https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00117&languageid=en-fr
To fix CVE-2018-3626, update your Intel SGX SDK to version 2.1.2 (Linux) or 1.9.6 (Windows) or later.