CVE-2019-7700: Medium severity webassembly binaryen vulnerability
Published Feb 10, 2019
·Updated
A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::visitCall in wasm-binary.cpp in Binaryen 1.38.22. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-merge.
Affected Software
1 affected component
Webassembly Binaryen<64
Remediation
Patch Available
Event History
Feb 10, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-7700.
2
What is the severity of CVE-2019-7700?
The severity of CVE-2019-7700 is medium with a severity value of 6.5.
3
How does CVE-2019-7700 affect the software?
CVE-2019-7700 affects the Webassembly Binaryen software version up to 64.
4
What is the description of CVE-2019-7700?
CVE-2019-7700 is a heap-based buffer over-read vulnerability in wasm::WasmBinaryBuilder::visitCall in wasm-binary.cpp in Binaryen 1.38.22 that can cause a segmentation fault leading to denial-of-service.
5
How can CVE-2019-7700 be exploited?
CVE-2019-7700 can be exploited by providing a crafted wasm input, leading to a segmentation fault and denial-of-service.