First published: Thu Dec 21 2017(Updated: )
In Netwide Assembler (NASM) 2.14rc0, there is a "SEGV on unknown address" that will cause a remote denial of service attack, because asm/preproc.c mishandles macro calls that have the wrong number of arguments.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nasm Netwide Assembler | =2.14-rc0 | |
Canonical Ubuntu Linux | =14.04 | |
debian/nasm | 2.15.05-1 2.16.01-1 2.16.03-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17810 is a vulnerability in Netwide Assembler (NASM) 2.14rc0 that can be exploited to cause a denial of service attack.
CVE-2017-17810 affects Netwide Assembler (NASM) 2.14rc0 and earlier versions, causing a denial of service attack when macro calls have the wrong number of arguments.
CVE-2017-17810 has a severity rating of medium.
To fix CVE-2017-17810, users should update to Netwide Assembler (NASM) version 2.15.05-1 or later.
Yes, you can find more information about CVE-2017-17810 at the following references: [http://repo.or.cz/nasm.git/commit/59ce1c67b16967c652765e62aa130b7e43f21dd4](http://repo.or.cz/nasm.git/commit/59ce1c67b16967c652765e62aa130b7e43f21dd4), [https://bugzilla.nasm.us/show_bug.cgi?id=3392431](https://bugzilla.nasm.us/show_bug.cgi?id=3392431), [https://usn.ubuntu.com/3694-1/](https://usn.ubuntu.com/3694-1/)