CVE-2021-36218: Buffer Overflow
An issue was discovered in SKALE sgxwallet 1.58.3. sgxdispippsAESGCMEncrypt allows an out-of-bounds write, resulting in a segfault and compromised enclave. This issue describes a buffer overflow, which was resolved prior to v1.77.0 and not reproducible in latest sgxwallet v1.77.0
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36218?
CVE-2021-36218 is considered a high severity vulnerability due to its potential for causing a segmentation fault and compromising the enclave.
How do I fix CVE-2021-36218?
To fix CVE-2021-36218, upgrade to SKALE sgxwallet version 1.77.0 or later.
What does CVE-2021-36218 affect?
CVE-2021-36218 affects SKALE sgxwallet version 1.58.3, which contains the buffer overflow vulnerability.
What type of vulnerability is CVE-2021-36218?
CVE-2021-36218 is a buffer overflow vulnerability that leads to out-of-bounds write issues.
Can I reproduce CVE-2021-36218 in newer versions of sgxwallet?
No, CVE-2021-36218 is not reproducible in SKALE sgxwallet version 1.77.0 or later.