7.1

CVE-2019-0122

Double free in Intel(R) SGX SDK for Linux before version 2.2 and Intel(R) SGX SDK for Windows before version 2.1 may allow an authenticated user to potentially enable information disclosure or denial of service via local access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Intel ≫ Software Guard Extensions Sdk Version < 2.1
   Microsoft ≫ Windows Version -
Intel ≫ Software Guard Extensions Sdk Version < 2.2
   Linux ≫ Linux Kernel Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.264
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 1.8 5.2
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
NIST 3.6 3.9 4.9
AV:L/AC:L/Au:N/C:P/I:N/A:P
CWE-415 Double Free

The product calls free() twice on the same memory address.

https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00217.html
Vendor Advisory