First published: Tue Dec 21 2021(Updated: )
A Denial of Service vulnerability exists in Binaryen 103 due to an Invalid memory address dereference in wasm::WasmBinaryBuilder::visitLet.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webassembly Binaryen | =103 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
=103 | ||
=34 | ||
=35 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-45293 is medium with a severity value of 5.5.
The affected software for CVE-2021-45293 includes Webassembly Binaryen version 103, Fedoraproject Fedora version 34, and Fedoraproject Fedora version 35.
To fix CVE-2021-45293, it is recommended to update to a patched version of the affected software.
More information about CVE-2021-45293 can be found at the following references: [GitHub Issue](https://github.com/WebAssembly/binaryen/issues/4384), [Fedora Advisory](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UKGCHPS7UAIOOBGSXDJAUFE5CROTTF6J/), [Fedora Advisory](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YCWLB4PWYQO55F7IGNC7KUYN2MFZE3JP/).
CWE-119 is a common weakness enumeration category that refers to Improper Restriction of Operations within the Bounds of a Memory Buffer.