CVE-2025-6273 Information

Description

A vulnerability was found in WebAssembly wabt up to 1.0.37 and classified as problematic. This issue affects the function LogOpcode of the file src/binary-reader-objdump.cc. The manipulation leads to reachable assertion. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The code maintainer explains that this issue might not affect eal world wasm programs.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Reference

https://github.com/user-attachments/files/19529411/wabt_crash.txt https://github.com/WebAssembly/wabt/issues/2574 https://vuldb.com/?ctiid.313277 https://vuldb.com/?id.313277 https://vuldb.com/?submit.593010

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

LOW

Base Severity

3.3

CNNVD-202506-2597 (Published: 2025-06-19)

Share on: