Описание
A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself.
A flaw was found in wabt. A local user can exploit an out-of-bounds read vulnerability by manipulating the wabt::Decompiler::VarName function within the wasm-decompile component. This can lead to information disclosure, denial of service, and potentially arbitrary code execution.
Отчет
This vulnerability is rated Moderate which exists in the wasm-decompile utility of the wabt package and requires local access to exploit. An attacker with local access could provide a specially crafted WebAssembly binary to the wasm-decompile tool, leading to an out-of-bounds read. This issue affects components like wabt in Fedora and firefox, thunderbird in Red Hat Enterprise Linux.
Дополнительная информация
Статус:
EPSS
7.1 High
CVSS3
Связанные уязвимости
A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself.
A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself.
A security vulnerability has been detected in WebAssembly wabt up to 1 ...
A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself.
EPSS
7.1 High
CVSS3