PT-2024-26487 · Wac · Wac
Haruki3Hhh
·
Published
2024-11-08
·
Updated
2024-11-12
·
CVE-2024-35419
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
wac version 385e1
Description
A heap overflow issue was discovered in the load module function at /wac-asan/wa.c, allowing attackers to cause a Denial of Service (DoS) via a crafted wasm file. The
load module function is vulnerable, and attackers can exploit this issue by providing a specially crafted wasm file.Recommendations
For version 385e1, consider disabling the
load module function as a temporary workaround until a patch is available. Restrict access to the /wac-asan/wa.c file to minimize the risk of exploitation. Avoid using crafted wasm files with the affected load module function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wac