Heap-based Buffer Overflow in WebAssembly Malformed File Handler by WABT
CVE-2025-2368

6.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
17 March 2025

What is CVE-2025-2368?

A heap-based buffer overflow vulnerability exists in the WebAssembly wabt version 1.0.36, specifically in the Malformed File Handler component. The issue arises in the wabt::interp::(anonymous namespace)::BinaryReaderInterp::OnExport function, located in the binary-reader-interp.cc file. This vulnerability can be exploited remotely, potentially allowing attackers to manipulate application behavior or gain unauthorized access. Immediate application of the available security patch is recommended to mitigate the risk of exploitation.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2025-2368 : Heap-based Buffer Overflow in WebAssembly Malformed File Handler by WABT