Out-of-Bound Memory Read in WebAssembly wbits 1.0.33 by WebAssembly
CVE-2023-46331

5.5MEDIUM

Key Information:

Vendor
CVE Published:
23 October 2023

What is CVE-2023-46331?

WebAssembly wabt version 1.0.33 contains a vulnerability that allows for an out-of-bound memory read in the DataSegment::IsValidRange() function. This flaw can lead to a segmentation fault, which may disrupt the operation of applications leveraging WebAssembly. It's essential for developers and security teams to be aware of this issue and implement necessary measures to safeguard their systems against potential exploitation.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-46331 : Out-of-Bound Memory Read in WebAssembly wbits 1.0.33 by WebAssembly