Denial of Service Vulnerability in Binaryen Software by WebAssembly
CVE-2019-7662

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
9 February 2019

What is CVE-2019-7662?

An assertion failure in the wasm::WasmBinaryBuilder::getType() function of the Binaryen library allows remote attackers to exploit crafted WebAssembly (wasm) files. This results in a denial of service scenario due to failed assertions leading to crashes, emphasizing the urgent need for assessments and mitigations regarding the usage of Binaryen version 1.38.22.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.