CVE-2017-17813: Use After Free
Published Dec 21, 2017
·Updated
In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in the pplistonemacro function in asm/preproc.c that will cause a remote denial of service attack, related to mishandling of line-syntax errors.
Affected Software
3 affected componentsFixes available
nasm Netwide Assembler=2.14-rc0
Canonical Ubuntu Linux=14.04
debian/nasm
2.15.05-12.16.01-12.16.03-13.01-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/nasmto a version that resolves this vulnerability.Fixed in 2.15.05-1Fixed in 2.16.01-1Fixed in 2.16.03-1Fixed in 3.01-1 - Upgrade
Upgrade
Netwide Assembler (NASM)to a version that resolves this vulnerability.Fixed in 2.14rc0
Event History
Dec 21, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Data Sourced
via NVD·03:29 AM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:34 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·08:00 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·08:01 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2017-17813.
2
What is the severity of CVE-2017-17813?
The severity of CVE-2017-17813 is medium.
3
What is the affected software?
The affected software is Netwide Assembler (NASM) version 2.14rc0.
4
How does CVE-2017-17813 affect the system?
CVE-2017-17813 can cause a remote denial of service attack.
5
How can I fix CVE-2017-17813?
To fix CVE-2017-17813, update Netwide Assembler (NASM) to version 2.13.02 or higher.