Out-of-Bounds Read in WebAssembly Interpreter by WebAssembly
CVE-2022-43280

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
28 October 2022

What is CVE-2022-43280?

An out-of-bounds read vulnerability has been identified in version 1.0.29 of the wasm-interp component, where an attacker can exploit the OnReturnCallExpr function to manipulate memory handling and potentially leak sensitive information. This flaw allows for unauthorized access to areas of memory that should be protected, increasing the risk of data exposure and application instability.

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-43280 : Out-of-Bounds Read in WebAssembly Interpreter by WebAssembly