Debian Binaryen vulnerabilities

24 known vulnerabilities affecting debian/binaryen.

Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM12LOW12

Vulnerabilities

Page 2 of 2
CVE-2019-7154MEDIUMCVSS 6.5fixed in binaryen 66-1 (bookworm)2019
CVE-2019-7154 [MEDIUM] CVE-2019-7154: binaryen - The main function in tools/wasm2js.cpp in Binaryen 1.38.22 has a heap-based buff... The main function in tools/wasm2js.cpp in Binaryen 1.38.22 has a heap-based buffer overflow because Emscripten is misused, triggering an error in cashew::JSPrinter::printAst() in emscripten-optimizer/simple_ast.h. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by wasm2js. Scope: local bookworm: resolved (fixed in 66-1)
debian
CVE-2019-7701MEDIUMCVSS 6.5fixed in binaryen 64-1 (bookworm)2019
CVE-2019-7701 [MEDIUM] CVE-2019-7701: binaryen - A heap-based buffer over-read was discovered in wasm::SExpressionParser::skipWhi... A heap-based buffer over-read was discovered in wasm::SExpressionParser::skipWhitespace() in wasm-s-parser.cpp in Binaryen 1.38.22. A crafted wasm input can cause a segmentation fault, leading to denial-of-service, as demonstrated by wasm2js. Scope: local bookworm: resolved (fixed in 64-1) bullseye: resolved (fixed in 64-1) forky: resolved (fixed in 64-1) sid: reso
debian
CVE-2019-15759LOWCVSS 6.5fixed in binaryen 89-1 (bookworm)2019
CVE-2019-15759 [MEDIUM] CVE-2019-15759: binaryen - An issue was discovered in Binaryen 1.38.32. Two visitors in ir/ExpressionManipu... An issue was discovered in Binaryen 1.38.32. Two visitors in ir/ExpressionManipulator.cpp can lead to a NULL pointer dereference in wasm::LocalSet::finalize in wasm/wasm.cpp. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by wasm2js. Scope: local bookworm: resolved (fixed in 89-1) bullseye: resolved (fixed in 89-1) fo
debian
CVE-2019-15758LOWCVSS 6.5fixed in binaryen 89-1 (bookworm)2019
CVE-2019-15758 [MEDIUM] CVE-2019-15758: binaryen - An issue was discovered in Binaryen 1.38.32. Missing validation rules in asmjs/a... An issue was discovered in Binaryen 1.38.32. Missing validation rules in asmjs/asmangle.cpp can lead to an Assertion Failure at wasm/wasm.cpp in wasm::asmangle. A crafted input can cause denial-of-service, as demonstrated by wasm2js. Scope: local bookworm: resolved (fixed in 89-1) bullseye: resolved (fixed in 89-1) forky: resolved (fixed in 89-1) sid: resolved (f
debian