CVE-2017-17815: Medium severity nasm Netwide Assembler vulnerability
In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in ismmacro() in asm/preproc.c that will cause a remote denial of service attack, because of a missing check for the relationship between minimum and maximum parameter counts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/nasmto a version that resolves this vulnerability.Fixed in 2.15.05-1Fixed in 2.16.01-1Fixed in 2.16.03-1Fixed in 3.01-1
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2017-17815.
What is the severity of CVE-2017-17815?
The severity of CVE-2017-17815 is medium with a severity value of 5.5.
What is the affected software?
The affected software is Netwide Assembler (NASM) version 2.14rc0.
How can I fix CVE-2017-17815?
To fix CVE-2017-17815, update to NASM version 2.13.02 or apply the necessary patches provided by your Linux distribution.
Where can I find more information about CVE-2017-17815?
You can find more information about CVE-2017-17815 in the references provided: http://repo.or.cz/nasm.git/commit/c9244eaadd05b27637cde06021bac3fa1d920aa3, https://bugzilla.nasm.us/show_bug.cgi?id=3392436, and https://usn.ubuntu.com/3694-1/.