CVE-2018-16770: High severity webassembly virtual machine vulnerability
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a denial of service (application crash) or possibly have unspecified other impact because a certain newallocator allocate call fails.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-16770?
CVE-2018-16770 has been categorized as a high severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2018-16770?
To mitigate CVE-2018-16770, upgrade WebAssembly Virtual Machine to a version released after July 26, 2018.
What types of issues can CVE-2018-16770 cause?
CVE-2018-16770 can cause application crashes and potentially other unknown impacts due to a failure in memory allocation handling.
Which versions of WebAssembly Virtual Machine are affected by CVE-2018-16770?
CVE-2018-16770 affects all versions of WebAssembly Virtual Machine up to and including 2018-07-26.
Is CVE-2018-16770 a zero-day vulnerability?
CVE-2018-16770 is not a zero-day vulnerability, as it was publicly disclosed before any patches were released.