CVE-2017-17816: Use After Free
In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in ppgetline in asm/preproc.c that will cause a remote denial of service attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/nasmto a version that resolves this vulnerability.Fixed in 2.15.05-1Fixed in 2.16.01-1Fixed in 2.16.03-1Fixed in 3.01-1
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2017-17816.
What is the severity of CVE-2017-17816?
The severity of CVE-2017-17816 is medium (5.5).
What is the affected software?
The affected software is Netwide Assembler (NASM) version 2.14rc0.
How can I fix CVE-2017-17816?
To fix CVE-2017-17816, upgrade to Netwide Assembler (NASM) version 2.14 or later.
Are there any additional references for CVE-2017-17816?
Yes, you can find additional references for CVE-2017-17816 at the following links: [Link 1](https://bugzilla.nasm.us/show_bug.cgi?id=3392426), [Link 2](https://usn.ubuntu.com/3694-1/), [Link 3](https://launchpad.net/bugs/cve/CVE-2017-17816).