First published: Thu Dec 21 2017(Updated: )
In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in do_directive in asm/preproc.c that will cause a remote denial of service attack.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nasm Netwide Assembler | =2.14-rc0 | |
Canonical Ubuntu Linux | =14.04 | |
debian/nasm | 2.15.05-1 2.16.01-1 2.16.03-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2017-17814.
The severity level of CVE-2017-17814 is medium (5.5).
The affected software versions of CVE-2017-17814 are Netwide Assembler (NASM) 2.14rc0, 2.13.02, 2.11.08-1ubuntu0.1, 2.13.01-2ubuntu0.1, and Canonical Ubuntu Linux 14.04 LTS.
To fix CVE-2017-17814, you should update Netwide Assembler (NASM) to version 2.14-1, 2.15.05-1, or 2.16.01-1.
You can find more information about CVE-2017-17814 on the following references: [Bugzilla](https://bugzilla.nasm.us/show_bug.cgi?id=3392430), [Ubuntu Security Notice](https://usn.ubuntu.com/3694-1/), and [Launchpad](https://launchpad.net/bugs/cve/CVE-2017-17814).