Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2019-7704

Description

wasm::WasmBinaryBuilder::readUserSection in wasm-binary.cpp in Binaryen 1.38.22 triggers an attempt at excessive memory allocation, as demonstrated by wasm-merge and wasm-opt.

POC

Reference

- https://github.com/WebAssembly/binaryen/issues/1866

Github

- https://github.com/fuzz-evaluator/MemLock-Fuzz-eval

- https://github.com/wcventure/MemLock-Fuzz