First published: Fri Oct 28 2022(Updated: )
wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDropKeepCount.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webassembly Wabt | =1.0.29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-43280 is high with a CVSS score of 7.1.
The software affected by CVE-2022-43280 is Webassembly Wabt v1.0.29.
CVE-2022-43280 is a vulnerability in wasm-interp v1.0.29 that allows an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDropKeepCount.
Currently, there is no known fix available for CVE-2022-43280. It is recommended to update to a patched version of the software once it becomes available.
More information about CVE-2022-43280 can be found at the following link: [https://github.com/WebAssembly/wabt/issues/1982]