CVE-2025-15412
Beschrijving NL
Er is een beveiligingsprobleem gedetecteerd in WebAssembly tot 1.0.39. Dit probleem heeft invloed op de functie wabt:: Decompiler::VarName van het bestand /src/repro/wabt/bin/wasm-decompile van de component wasm-decompile. Dergelijke manipulatie leidt tot lezen buiten de grenzen. Lokale toegang is vereist om deze aanval te benaderen. De exploit is openbaar gemaakt en kan worden gebruikt. Helaas heeft het project op dit moment geen actieve onderhouder. In een reactie op het probleemrapport raadde iemand de onderzoeker aan om zelf een PR te verzorgen.
Origineel (Engels) tonen
A security vulnerability has been detected in WebAssembly wabt up to 1.0.39. This issue affects the function wabt::Decompiler::VarName of the file /src/repro/wabt/bin/wasm-decompile of the component wasm-decompile. Such manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. Unfortunately, the project has no active maintainer at the moment. In a reply to the issue report somebody recommended to the researcher to provide a PR himself.