First published: Sat Jul 08 2017(Updated: )
In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nasm Netwide Assembler | =2.14-rc0 | |
Canonical Ubuntu Linux | =14.04 | |
debian/nasm | 2.15.05-1 2.16.01-1 2.16.03-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID of this vulnerability is CVE-2017-11111.
The severity level of CVE-2017-11111 is high (7.8).
The affected software is Netwide Assembler (NASM) version 2.14rc0.
This vulnerability can be exploited by remote attackers to cause a denial of service or have other unspecified impacts via a crafted file.
Yes, for Debian, the version 2.14-1, 2.15.05-1, and 2.16.01-1 of NASM have the remedy. For Ubuntu, the version 2.13.01-2ubuntu0.1 has the remedy for Ubuntu artful. Additionally, versions 2.10.09-1ubuntu0.1 and 2.11.08-1ubuntu0.1 have the remedy for Ubuntu trusty and xenial respectively.