CVE-2019-15759: Null Pointer Dereference
Published Aug 29, 2019
·Updated
An issue was discovered in Binaryen 1.38.32. Two visitors in ir/ExpressionManipulator.cpp can lead to a NULL pointer dereference in wasm::LocalSet::finalize in wasm/wasm.cpp. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by wasm2js.
Affected Software
1 affected component
Webassembly Binaryen<89
Remediation
Patch Available
Patch Available
Event History
Aug 29, 2019
CVE Published
via MITRE·01:01 AM
Data Sourced
via MITRE·01:01 AM
Description
Frequently Asked Questions
1
What is CVE-2019-15759?
CVE-2019-15759 is a vulnerability in Binaryen 1.38.32 that can lead to a NULL pointer dereference in wasm::LocalSet::finalize in wasm/wasm.cpp.
2
How severe is CVE-2019-15759?
CVE-2019-15759 has a severity rating of 6.5 (medium).
3
How does CVE-2019-15759 affect Binaryen?
CVE-2019-15759 affects Binaryen versions up to exclusive version 89.
4
What is the impact of CVE-2019-15759?
A crafted input can cause segmentation faults, leading to denial-of-service.
5
How can CVE-2019-15759 be fixed?
Update to a version of Binaryen that is higher than version 89 to mitigate CVE-2019-15759.