CVE-2023-27117: High severity webassembly virtual machine vulnerability
Published Mar 10, 2023
·Updated
WebAssembly v1.0.29 was discovered to contain a heap overflow via the component component wabt::Node::operator.
Affected Software
1 affected component
WebAssembly WebAssembly=1.0.29
Event History
Mar 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-27117?
CVE-2023-27117 is a vulnerability in WebAssembly v1.0.29 that allows a heap overflow via the component wabt::Node::operator.
2
What is the severity of CVE-2023-27117?
The severity of CVE-2023-27117 is high with a severity score of 7.8.
3
How does CVE-2023-27117 affect WebAssembly?
CVE-2023-27117 affects WebAssembly v1.0.29 and can lead to a heap overflow through the component wabt::Node::operator.
4
How can I fix CVE-2023-27117?
To fix CVE-2023-27117, it is recommended to update to a version of WebAssembly that is not affected by the vulnerability.
5
Where can I find more information about CVE-2023-27117?
More information about CVE-2023-27117 can be found at: https://github.com/WebAssembly/wabt/issues/1989.