Null Pointer Dereference in Binaryen Software from WebAssembly
CVE-2020-18378
6.5MEDIUM
What is CVE-2020-18378?
A NULL pointer dereference vulnerability was identified in the SExpressionWasmBuilder::makeBlock function in Binaryen 1.38.26. This flaw allows attackers to craft special wasm inputs that trigger a segmentation fault, which subsequently results in a denial-of-service condition. The vulnerability's impact has been demonstrated utilizing the wasm-as utility.
