PT-2024-26487 · Wac · Wac

Haruki3Hhh

·

Published

2024-11-08

·

Updated

2024-11-12

·

CVE-2024-35419

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions wac version 385e1
Description A heap overflow issue was discovered in the load module function at /wac-asan/wa.c, allowing attackers to cause a Denial of Service (DoS) via a crafted wasm file. The load module function is vulnerable, and attackers can exploit this issue by providing a specially crafted wasm file.
Recommendations For version 385e1, consider disabling the load module function as a temporary workaround until a patch is available. Restrict access to the /wac-asan/wa.c file to minimize the risk of exploitation. Avoid using crafted wasm files with the affected load module function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-35419

Affected Products

Wac