Lucene search

K
ubuntucveUbuntu.comUB:CVE-2020-18382
HistoryAug 22, 2023 - 12:00 a.m.

CVE-2020-18382

2023-08-2200:00:00
ubuntu.com
ubuntu.com
3
cve-2020-18382
segmentation fault
denial of service
wasm-opt
unix
crafted wasm input

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

27.8%

Heap-buffer-overflow in /src/wasm/wasm-binary.cpp in
wasm::WasmBinaryBuilder::visitBlock(wasm::Block*) in Binaryen 1.38.26. A
crafted wasm input can cause a segmentation fault, leading to
denial-of-service, as demonstrated by wasm-opt.

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

27.8%

Related for UB:CVE-2020-18382