An heap overflow vulnerability was discovered in Bytecode alliance wasm-micro-runtime v.1.2.3 allows a remote attacker to cause a denial of service via the wasm_loader_prepare_bytecode function in core/iwasm/interpreter/wasm_loader.c.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://bytecode.com | not applicable |
http://wasm-micro-runtime.com | broken link |
https://github.com/bytecodealliance/wasm-micro-runtime/issues/2726 | patch issue tracking exploit |
https://github.com/bytecodealliance/wasm-micro-runtime/pull/2734/commits/4785d91b16dd49c09a96835de2d9c7b077543fa4 | patch |