CVE-2019-7700
published 2019-02-10CVE-2019-7700: A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::visitCall in wasm-binary.cpp in Binaryen 1.38.22. A crafted wasm input can cause a…
PriorityP426medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
1.15%
63.4th percentile
A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::visitCall in wasm-binary.cpp in Binaryen 1.38.22. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-merge.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binaryen | < binaryen 64-1 (bookworm) | binaryen 64-1 (bookworm) |
| webassembly | binaryen | < 64 | 64 |
| webassembly | binaryen | >= 0 < 64-1 | 64-1 |
| webassembly | binaryen | >= 0 < 64-1 | 64-1 |
| webassembly | binaryen | >= 0 < 64-1 | 64-1 |
| webassembly | binaryen | >= 0 < 64-1 | 64-1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_cisco6.7MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ggj8-g5w9-5x4p: A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::visitCall in wasm-binary
ghsa_unreviewed·2022-05-13
CVE-2019-7700 [MEDIUM] CWE-125 GHSA-ggj8-g5w9-5x4p: A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::visitCall in wasm-binary
A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::visitCall in wasm-binary.cpp in Binaryen 1.38.22. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-merge.
OSV
CVE-2019-7700: A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::visitCall in wasm-binary
osv·2019-02-10·CVSS 6.5
CVE-2019-7700 [MEDIUM] CVE-2019-7700: A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::visitCall in wasm-binary
A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::visitCall in wasm-binary.cpp in Binaryen 1.38.22. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-merge.
Cisco
Cisco MDS 9700 Series Multilayer Directors and Nexus 7000/7700 Series Switches Software Patch Signature Verification Vulnerability
vendor_cisco·2019-05-15·CVSS 6.7
CVE-2019-1808 [MEDIUM] CWE-347 Cisco MDS 9700 Series Multilayer Directors and Nexus 7000/7700 Series Switches Software Patch Signature Verification Vulnerability
Cisco MDS 9700 Series Multilayer Directors and Nexus 7000/7700 Series Switches Software Patch Signature Verification Vulnerability
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software patch on an affected device.
The vulnerability is due to improper verification of digital signatures for patch images. An attacker could exploit this vulnerability by loading an unsigned software patch on an affected device. A successful exploit could allow the attacker to boot a malicious software patch image.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at
Debian
CVE-2019-7700: binaryen - A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::visitCa...
vendor_debian·2019·CVSS 6.5
CVE-2019-7700 [MEDIUM] CVE-2019-7700: binaryen - A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::visitCa...
A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::visitCall in wasm-binary.cpp in Binaryen 1.38.22. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm-merge.
Scope: local
bookworm: resolved (fixed in 64-1)
bullseye: resolved (fixed in 64-1)
forky: resolved (fixed in 64-1)
sid: resolved (fixed in 64-1)
trixie: resolved (fixed in 64-1)
Cisco
Cisco MDS 9700 Series Multilayer Directors and Nexus 7000/7700 Series Switches Software Patch Signature Verification Vulnerability
vendor_cisco·CVSS 3.0
CVE-2019-1808 Cisco MDS 9700 Series Multilayer Directors and Nexus 7000/7700 Series Switches Software Patch Signature Verification Vulnerability
CVE-2019-1808: Cisco MDS 9700 Series Multilayer Directors and Nexus 7000/7700 Series Switches Software Patch Signature Verification Vulnerability
A vulnerability in the Image Signature Verification feature of Cisco NX-OS Software could allow an authenticated, local attacker with administrator-level credentials to install a malicious software patch on an affected device. The vulnerability is due to improper verification of digital signatures for patch images. An attacker could exploit this vulnerability by loading an unsigned software patch on an affected device. A successful exploit could allow the attacker to boot a malicious software patch image. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.0
CWE: CWE-347, CWE-347
Bug IDs: CSCvi42248, CSCvi422
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-02-10
Published