Heap-Based Buffer Over-Read in Binaryen by WebAssembly
CVE-2019-7152

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
29 January 2019

What is CVE-2019-7152?

A heap-based buffer over-read vulnerability has been identified in Binaryen, specifically within the wasm::WasmBinaryBuilder::processFunctions() method. When improperly processed inputs are provided, this flaw can trigger segmentation faults that may lead to denial-of-service. This issue highlights the importance of rigorous input validation in tools handling WebAssembly binaries to prevent interruption of service.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.