Edger8r tool in the Intel SGX SDK before version 2.1.2 (Linux) and 1.9.6 (Windows) may generate code that is susceptible to a side channel potentially allowing a local user to access unauthorized information.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/103479 | vdb entry third party advisory |
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00117&languageid=en-fr | vendor advisory |