CVE-2017-17812: Medium severity nasm Netwide Assembler vulnerability
In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read in the function detoken() in asm/preproc.c that will cause a remote denial of service attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/nasmto a version that resolves this vulnerability.Fixed in 2.15.05-1Fixed in 2.16.01-1Fixed in 2.16.03-1Fixed in 3.01-1
Event History
Frequently Asked Questions
What is CVE-2017-17812?
CVE-2017-17812 is a vulnerability in Netwide Assembler (NASM) 2.14rc0 that allows a remote denial of service attack.
How severe is CVE-2017-17812?
CVE-2017-17812 has a severity rating of 5.5, which is considered medium.
How can I fix CVE-2017-17812?
To fix CVE-2017-17812, upgrade to NASM version 2.13.02 or apply the recommended patches from the respective Linux distribution.
Where can I find more information about CVE-2017-17812?
You can find more information about CVE-2017-17812 at the following references: [Reference 1](http://repo.or.cz/nasm.git/commit/9b7ee09abfd426b99aa1ea81d19a3b2818eeabf9), [Reference 2](https://bugzilla.nasm.us/show_bug.cgi?id=3392424), [Reference 3](https://usn.ubuntu.com/3694-1/)
What is the Common Weakness Enumeration (CWE) for CVE-2017-17812?
The Common Weakness Enumeration (CWE) for CVE-2017-17812 is CWE-125.