CVE-2017-11111: Buffer Overflow
In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2017-11111.
What is the severity level of CVE-2017-11111?
The severity level of CVE-2017-11111 is high (7.8).
What is the affected software?
The affected software is Netwide Assembler (NASM) version 2.14rc0.
How can this vulnerability be exploited?
This vulnerability can be exploited by remote attackers to cause a denial of service or have other unspecified impacts via a crafted file.
Are there any remedies available for this vulnerability?
Yes, for Debian, the version 2.14-1, 2.15.05-1, and 2.16.01-1 of NASM have the remedy. For Ubuntu, the version 2.13.01-2ubuntu0.1 has the remedy for Ubuntu artful. Additionally, versions 2.10.09-1ubuntu0.1 and 2.11.08-1ubuntu0.1 have the remedy for Ubuntu trusty and xenial respectively.