CVE-2019-7703: Use After Free
Published Feb 10, 2019
·Updated
In Binaryen 1.38.22, there is a use-after-free problem in wasm::WasmBinaryBuilder::visitCall in wasm-binary.cpp. Remote attackers could leverage this vulnerability to cause a denial-of-service via a wasm file, as demonstrated by wasm-merge.
Affected Software
1 affected component
Webassembly Binaryen<64
Remediation
Patch Available
Event History
Feb 10, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2019-7703?
CVE-2019-7703 is a use-after-free vulnerability in Binaryen 1.38.22.
2
How can this vulnerability impact me?
This vulnerability can be exploited by remote attackers to cause a denial-of-service by using a wasm file.
3
What is the affected software?
The affected software is Webassembly Binaryen version up to 64.
4
What is the severity rating of CVE-2019-7703?
The severity rating of CVE-2019-7703 is medium with a score of 6.5.
5
How can I fix CVE-2019-7703?
To fix CVE-2019-7703, it is recommended to update Binaryen to version 1.38.23 or later.