CVE-2019-15758: Medium severity webassembly binaryen vulnerability
Published Aug 29, 2019
·Updated
An issue was discovered in Binaryen 1.38.32. Missing validation rules in asmjs/asmangle.cpp can lead to an Assertion Failure at wasm/wasm.cpp in wasm::asmangle. A crafted input can cause denial-of-service, as demonstrated by wasm2js.
Affected Software
1 affected component
Webassembly Binaryen<89
Remediation
Patch Available
Patch Available
Event History
Aug 29, 2019
CVE Published
via MITRE·01:02 AM
Data Sourced
via MITRE·01:02 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue in Binaryen?
This vulnerability is identified by CVE-2019-15758.
2
What is the severity of CVE-2019-15758?
The severity of this vulnerability is medium, with a CVSS score of 6.5.
3
What is the affected software?
The affected software is Webassembly Binaryen version up to exclusive 89.
4
What is the impact of this vulnerability?
This vulnerability can be exploited to cause denial-of-service.
5
Are there any references available for more information on CVE-2019-15758?
Yes, you can find more information on this vulnerability at the following links: [GitHub Issue](https://github.com/WebAssembly/binaryen/issues/2288) and [GitHub Pull Request](https://github.com/WebAssembly/binaryen/pull/2290).