First published: Fri Oct 28 2022(Updated: )
wasm-interp v1.0.29 was discovered to contain a heap overflow via the component std::vector<wabt::Type, std::allocator<wabt::Type>>::size() at /bits/stl_vector.h.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webassembly Wasm | =1.0.29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43281 is a vulnerability in wasm-interp v1.0.29 that allows a heap overflow via the component std::vector<wabt::Type, std::allocator<wabt::Type>>::size().
CVE-2022-43281 has a severity rating of 7.8 (high).
CVE-2022-43281 affects Webassembly Wasm v1.0.29.
There is currently no fix available for CVE-2022-43281. It is recommended to update to a version of wasm-interp that is not affected by this vulnerability when it becomes available.
You can find more information about CVE-2022-43281 on the GitHub issue page: https://github.com/WebAssembly/wabt/issues/1981