CVE-2019-7701: Medium severity webassembly binaryen vulnerability
Published Feb 10, 2019
·Updated
A heap-based buffer over-read was discovered in wasm::SExpressionParser::skipWhitespace() in wasm-s-parser.cpp in Binaryen 1.38.22. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm2js.
Affected Software
1 affected component
Webassembly Binaryen<64
Remediation
Patch Available
Event History
Feb 10, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this heap-based buffer over-read?
The vulnerability ID is CVE-2019-7701.
2
What software is affected by this vulnerability?
The affected software is Webassembly Binaryen.
3
What is the severity of CVE-2019-7701?
The severity of CVE-2019-7701 is medium with a severity value of 6.5.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by sending a crafted wasm input, leading to a segmentation fault and denial-of-service.
5
Is there a fix available for this vulnerability?
Yes, the fix for this vulnerability is available in version 1.38.23 or later of Binaryen.