First published: Tue Jan 29 2019(Updated: )
A NULL pointer dereference was discovered in wasm::WasmBinaryBuilder::processFunctions() in wasm/wasm-binary.cpp (when calling wasm::WasmBinaryBuilder::getFunctionIndexName) in Binaryen 1.38.22. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by wasm-opt.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WebAssembly Binaryen | <65 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-7153 is medium with a severity value of 6.5.
The affected software for CVE-2019-7153 is Webassembly Binaryen version up to exclusive 65.
CVE-2019-7153 is a NULL pointer dereference vulnerability in wasm::WasmBinaryBuilder::processFunctions() in wasm/wasm-binary.cpp, allowing crafted input to cause segmentation faults and denial-of-service.
To exploit CVE-2019-7153, a crafted input can be used to cause segmentation faults, leading to denial-of-service.
It is recommended to update to a version of Webassembly Binaryen beyond 1.38.22 to mitigate the vulnerability in CVE-2019-7153.