CVE-2019-7704: Medium severity webassembly binaryen vulnerability
wasm::WasmBinaryBuilder::readUserSection in wasm-binary.cpp in Binaryen 1.38.22 triggers an attempt at excessive memory allocation, as demonstrated by wasm-merge and wasm-opt.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is vulnerability CVE-2019-7704?
Vulnerability CVE-2019-7704 is a memory allocation vulnerability in Binaryen 1.38.22's wasm::WasmBinaryBuilder::readUserSection function.
How does vulnerability CVE-2019-7704 occur?
Vulnerability CVE-2019-7704 occurs due to an attempt at excessive memory allocation in wasm::WasmBinaryBuilder::readUserSection.
What is the severity of vulnerability CVE-2019-7704?
Vulnerability CVE-2019-7704 has a severity rating of medium (6.5).
How can I fix vulnerability CVE-2019-7704?
To fix vulnerability CVE-2019-7704, update to a version of Binaryen that is newer than 1.38.22.
Where can I find more information about vulnerability CVE-2019-7704?
More information about vulnerability CVE-2019-7704 can be found at the following link: [https://github.com/WebAssembly/binaryen/issues/1866](https://github.com/WebAssembly/binaryen/issues/1866)