CVE-2022-43282: High severity WebAssembly wabt vulnerability
Published Oct 28, 2022
·Updated
wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallIndirectExpr->GetReturnCallDropKeepCount.
Affected Software
1 affected component
WebAssembly wabt=1.0.29
Remediation
Patch Available
Event History
Oct 28, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID for this issue is CVE-2022-43282.
2
What is the severity of CVE-2022-43282?
The severity of CVE-2022-43282 is high, with a CVSS score of 7.1.
3
What software is affected by CVE-2022-43282?
wasm-interp v1.0.29, specifically the Webassembly Wabt component, is affected by CVE-2022-43282.
4
What is the description of CVE-2022-43282?
CVE-2022-43282 is an out-of-bounds read vulnerability discovered in wasm-interp v1.0.29 through the component OnReturnCallIndirectExpr->GetReturnCallDropKeepCount.
5
Is there a fix available for CVE-2022-43282?
At the time of this writing, a fix has not been released for CVE-2022-43282. It is recommended to follow the official vendor's advisories for updates.