CVE-2020-0561
published 2020-02-13CVE-2020-0561: Improper initialization in the Intel(R) SGX SDK before v2.6.100.1 may allow an authenticated user to potentially enable escalation of privilege via local…
PriorityP434high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.41%
33.2th percentile
Improper initialization in the Intel(R) SGX SDK before v2.6.100.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | software_guard_extensions_sdk | < 2.6.100.1 | 2.6.100.1 |
| intel | software_guard_extensions_sdk | < 2.8.100.1 | 2.8.100.1 |
| opensuse | backports | — | — |
| opensuse | leap | — | — |
| paloalto | pan-os | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN
vendor_paloalto·2020-04-08·CVSS 6.7
CVE-2019-0139 [MEDIUM] PAN
PAN
Palo Alto Networks Product Security Assurance team has evaluated and determined that these third-party or open source vulnerabilities do not have a security impact on Palo Alto Networks Products, or the scenarios required for successful
CVEs: CVE-2019-0139, CVE-2019-0140, CVE-2019-0142, CVE-2019-0143, CVE-2019-0144, CVE-2019-0145, CVE-2019-0146, CVE-2019-0147, CVE-2019-0148, CVE-2019-0149, CVE-2019-0150, CVE-2019-11168, CVE-2019-11170, CVE-2019-11171, CVE-2019-11172, CVE-2019-11173, CVE-2019-11174, CVE-2019-11175, CVE-2019-11177, CVE-2019-11178, CVE-2019-11179, CVE-2019-11180, CVE-2019-11181, CVE-2019-11182, CVE-2019-12735, CVE-2019-16905, CVE-2020-0561, CVE-2020-0562, CVE-2020-0563, CVE-2020-0564
Affected products: PAN-OS
GHSA
GHSA-r4p7-pmgm-2v37: Improper initialization in the Intel(R) SGX SDK before v2
ghsa_unreviewed·2022-05-24
CVE-2020-0561 [MEDIUM] CWE-665 GHSA-r4p7-pmgm-2v37: Improper initialization in the Intel(R) SGX SDK before v2
Improper initialization in the Intel(R) SGX SDK before v2.6.100.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
OSV
tiff vulnerabilities
osv·2022-05-16·CVSS 5.5
CVE-2020-35522 tiff vulnerabilities
tiff vulnerabilities
It was discovered that LibTIFF incorrectly handled certain images.
An attacker could possibly use this issue to cause a crash,
resulting in a denial of service. This issue only affects
Ubuntu 14.04 ESM, Ubuntu 16.04 ESM, Ubuntu 18.04 LTS and
Ubuntu 20.04 LTS. (CVE-2020-35522)
Chintan Shah discovered that LibTIFF incorrectly handled memory when
handling certain images. An attacker could possibly use this issue to
cause a crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2022-0561, CVE-2022-0562, CVE-2022-0891)
It was discovered that LibTIFF incorrectly handled certain images.
An attacker could possibly use this issue to cause a crash,
resulting in a denial of service. This issue only affects
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubunt
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00014.htmlhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00336.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00009.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-05/msg00014.htmlhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00336.html
2020-02-13
Published