Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-7154

Опубликовано: 29 янв. 2019
Источник: nvd
CVSS3: 6.5
CVSS2: 4.3
EPSS Низкий

Описание

The main function in tools/wasm2js.cpp in Binaryen 1.38.22 has a heap-based buffer overflow because Emscripten is misused, triggering an error in cashew::JSPrinter::printAst() in emscripten-optimizer/simple_ast.h. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by wasm2js.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:webassembly:binaryen:*:*:*:*:*:*:*:*
Версия до 65 (исключая)

EPSS

Процентиль: 62%
0.00427
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 7 лет назад

The main function in tools/wasm2js.cpp in Binaryen 1.38.22 has a heap-based buffer overflow because Emscripten is misused, triggering an error in cashew::JSPrinter::printAst() in emscripten-optimizer/simple_ast.h. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by wasm2js.

CVSS3: 6.5
debian
около 7 лет назад

The main function in tools/wasm2js.cpp in Binaryen 1.38.22 has a heap- ...

CVSS3: 6.5
github
больше 3 лет назад

The main function in tools/wasm2js.cpp in Binaryen 1.38.22 has a heap-based buffer overflow because Emscripten is misused, triggering an error in cashew::JSPrinter::printAst() in emscripten-optimizer/simple_ast.h. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by wasm2js.

EPSS

Процентиль: 62%
0.00427
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-787