CVE-2022-43280: High severity WebAssembly wabt vulnerability
Published Oct 28, 2022
·Updated
wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDropKeepCount.
Affected Software
1 affected component
WebAssembly wabt=1.0.29
Remediation
Patch Available
Event History
Oct 28, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-43280?
The severity of CVE-2022-43280 is high with a CVSS score of 7.1.
2
What software is affected by CVE-2022-43280?
The software affected by CVE-2022-43280 is Webassembly Wabt v1.0.29.
3
What is the vulnerability described in CVE-2022-43280?
CVE-2022-43280 is a vulnerability in wasm-interp v1.0.29 that allows an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDropKeepCount.
4
Are there any fixes available for CVE-2022-43280?
Currently, there is no known fix available for CVE-2022-43280. It is recommended to update to a patched version of the software once it becomes available.
5
Where can I find more information about CVE-2022-43280?
More information about CVE-2022-43280 can be found at the following link: [https://github.com/WebAssembly/wabt/issues/1982]