CVE-2017-17814: Use After Free
In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in dodirective in asm/preproc.c that will cause a remote denial of service attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/nasmto a version that resolves this vulnerability.Fixed in 2.15.05-1Fixed in 2.16.01-1Fixed in 2.16.03-1Fixed in 3.01-1
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2017-17814.
What is the severity level of CVE-2017-17814?
The severity level of CVE-2017-17814 is medium (5.5).
Which software versions are affected by CVE-2017-17814?
The affected software versions of CVE-2017-17814 are Netwide Assembler (NASM) 2.14rc0, 2.13.02, 2.11.08-1ubuntu0.1, 2.13.01-2ubuntu0.1, and Canonical Ubuntu Linux 14.04 LTS.
How can I fix CVE-2017-17814?
To fix CVE-2017-17814, you should update Netwide Assembler (NASM) to version 2.14-1, 2.15.05-1, or 2.16.01-1.
Where can I find more information about CVE-2017-17814?
You can find more information about CVE-2017-17814 on the following references: [Bugzilla](https://bugzilla.nasm.us/show_bug.cgi?id=3392430), [Ubuntu Security Notice](https://usn.ubuntu.com/3694-1/), and [Launchpad](https://launchpad.net/bugs/cve/CVE-2017-17814).