We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-3122

WebAssembly wabt binary-reader-interp.cc BeginFunctionBody null pointer dereference



Description

EN DE

A vulnerability classified as problematic was found in WebAssembly wabt 1.0.36. Affected by this vulnerability is the function BinaryReaderInterp::BeginFunctionBody of the file src/interp/binary-reader-interp.cc. The manipulation leads to null pointer dereference. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

In WebAssembly wabt 1.0.36 wurde eine problematische Schwachstelle entdeckt. Dabei geht es um die Funktion BinaryReaderInterp::BeginFunctionBody der Datei src/interp/binary-reader-interp.cc. Durch das Manipulieren mit unbekannten Daten kann eine null pointer dereference-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Die Komplexität eines Angriffs ist eher hoch. Sie gilt als schwierig ausnutzbar. Der Exploit steht zur öffentlichen Verfügung.

Reserved 2025-04-02 | Published 2025-04-02 | Updated 2025-04-03 | Assigner VulDB


LOW: 2.3CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
LOW: 3.1CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
LOW: 3.1CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
2.6AV:N/AC:H/Au:N/C:N/I:N/A:P

Problem types

NULL Pointer Dereference

Denial of Service

Product status

1.0.36
affected

Timeline

2025-04-02:Advisory disclosed
2025-04-02:VulDB entry created
2025-04-02:VulDB entry last update

References

vuldb.com/?id.303013 (VDB-303013 | WebAssembly wabt binary-reader-interp.cc BeginFunctionBody null pointer dereference) vdb-entry technical-description

vuldb.com/?ctiid.303013 (VDB-303013 | CTI Indicators (IOB, IOC, IOA)) signature permissions-required

vuldb.com/?submit.525091 (Submit #525091 | https://github.com/WebAssembly/wabt wabt 1.0.36 NULL Pointer Dereference) third-party-advisory

github.com/WebAssembly/wabt/issues/2565 issue-tracking

github.com/WebAssembly/wabt/issues/2565 exploit issue-tracking

cve.org (CVE-2025-3122)

nvd.nist.gov (CVE-2025-3122)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-3122

Support options

Helpdesk Chat, Email, Knowledgebase