First published: Mon Sep 10 2018(Updated: )
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because a certain new_allocator allocate call fails.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WebAssembly Virtual Machine | <=2018-07-26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16770 has been categorized as a high severity vulnerability due to its potential to cause a denial of service.
To mitigate CVE-2018-16770, upgrade WebAssembly Virtual Machine to a version released after July 26, 2018.
CVE-2018-16770 can cause application crashes and potentially other unknown impacts due to a failure in memory allocation handling.
CVE-2018-16770 affects all versions of WebAssembly Virtual Machine up to and including 2018-07-26.
CVE-2018-16770 is not a zero-day vulnerability, as it was publicly disclosed before any patches were released.