Heap-based Buffer Over-read Vulnerability in WAVM by Andrew Scheidecker
CVE-2018-16764

8.8HIGH

What is CVE-2018-16764?

A crafted file sent to the WebAssembly Virtual Machine can exploit a flaw in the IR::FunctionValidationContext::catch_all component, which may result in a denial of service due to an application crash. This vulnerability occurs in WAVM versions released prior to July 26, 2018, and can potentially lead to further unspecified impacts.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2018-16764 : Heap-based Buffer Over-read Vulnerability in WAVM by Andrew Scheidecker