CVE-2022-43281: High severity WebAssembly Wasm vulnerability
Published Oct 28, 2022
·Updated
wasm-interp v1.0.29 was discovered to contain a heap overflow via the component std::vector<wabt::Type, std::allocator<wabt::Type>>::size() at /bits/stlvector.h.
Affected Software
1 affected component
WebAssembly Wasm=1.0.29
Remediation
Patch Available
Event History
Oct 28, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-43281?
CVE-2022-43281 is a vulnerability in wasm-interp v1.0.29 that allows a heap overflow via the component std::vector<wabt::Type, std::allocator<wabt::Type>>::size().
2
How severe is CVE-2022-43281?
CVE-2022-43281 has a severity rating of 7.8 (high).
3
Which software versions are affected by CVE-2022-43281?
CVE-2022-43281 affects Webassembly Wasm v1.0.29.
4
How can I fix CVE-2022-43281?
There is currently no fix available for CVE-2022-43281. It is recommended to update to a version of wasm-interp that is not affected by this vulnerability when it becomes available.
5
Where can I find more information about CVE-2022-43281?
You can find more information about CVE-2022-43281 on the GitHub issue page: https://github.com/WebAssembly/wabt/issues/1981