First published: Mon Sep 10 2018(Updated: )
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because of an unspecified "heap-buffer-overflow" condition in IR::FunctionValidationContext::end.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WebAssembly Virtual Machine | <=2018-07-26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16768 has a severity rating that indicates it may lead to a denial of service due to a heap buffer overflow.
To mitigate CVE-2018-16768, you should update to a version of the WebAssembly Virtual Machine released after July 26, 2018.
CVE-2018-16768 could cause an application crash or potentially lead to other unspecified adverse effects.
Users of the WebAssembly Virtual Machine project versions up to and including July 26, 2018, are affected by CVE-2018-16768.
CVE-2018-16768 involves a heap buffer overflow condition during the validation context of WebAssembly functions.