CVE-2018-16768: Buffer Overflow
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an unspecified "heap-buffer-overflow" condition in IR::FunctionValidationContext::end.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-16768?
CVE-2018-16768 has a severity rating that indicates it may lead to a denial of service due to a heap buffer overflow.
How do I fix CVE-2018-16768?
To mitigate CVE-2018-16768, you should update to a version of the WebAssembly Virtual Machine released after July 26, 2018.
What impact could CVE-2018-16768 have on my application?
CVE-2018-16768 could cause an application crash or potentially lead to other unspecified adverse effects.
Who is affected by CVE-2018-16768?
Users of the WebAssembly Virtual Machine project versions up to and including July 26, 2018, are affected by CVE-2018-16768.
What is the nature of the flaw in CVE-2018-16768?
CVE-2018-16768 involves a heap buffer overflow condition during the validation context of WebAssembly functions.