CVE-2018-16766: High severity webassembly virtual machine vulnerability
Published Sep 10, 2018
·Updated
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because Errors::unreachable() is reached.
Affected Software
1 affected component
Webassembly Virtual Machine Project Webassembly Virtual Machine<=2018-07-26
Remediation
Patch Available
Event History
Sep 10, 2018
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16766?
CVE-2018-16766 has a medium severity as it can cause a denial of service through application crashes.
2
How do I fix CVE-2018-16766?
To fix CVE-2018-16766, update to a version of the WebAssembly Virtual Machine that is released after July 26, 2018.
3
What type of vulnerability is CVE-2018-16766?
CVE-2018-16766 is categorized as a denial of service vulnerability.
4
What impact can CVE-2018-16766 have on my application?
CVE-2018-16766 can lead to application crashes and may potentially allow for unspecified other impacts.
5
How can CVE-2018-16766 be exploited?
CVE-2018-16766 can be exploited by sending crafted files to the WebAssembly Virtual Machine.