Heap Buffer Overflow in Binaryen Affects WebAssembly Processing
CVE-2020-18382

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
22 August 2023

What is CVE-2020-18382?

A heap buffer overflow vulnerability exists in Binaryen's wasm::WasmBinaryBuilder::visitBlock function, impacting version 1.38.26. This vulnerability can be exploited through crafted WebAssembly (wasm) inputs, potentially causing a segmentation fault. The result is a denial-of-service condition, which could disrupt the normal functioning of applications relying on Binaryen for wasm processing. Detailed discussions and issues related to this vulnerability are documented in the Binaryen GitHub repository.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-18382 : Heap Buffer Overflow in Binaryen Affects WebAssembly Processing