CVE-2017-17817: Use After Free
In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in ppverror in asm/preproc.c that will cause a remote denial of service attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/nasmto a version that resolves this vulnerability.Fixed in 2.15.05-1Fixed in 2.16.01-1Fixed in 2.16.03-1Fixed in 3.01-1
Event History
Frequently Asked Questions
What is CVE-2017-17817?
CVE-2017-17817 is a vulnerability in Netwide Assembler (NASM) 2.14rc0 that allows for a remote denial of service attack due to a use-after-free vulnerability in pp_verror in asm/preproc.c.
How severe is CVE-2017-17817?
CVE-2017-17817 has a severity rating of 5.5 (medium).
Which software versions are affected?
Versions 2.14rc0 and newer of Netwide Assembler (NASM) are affected by CVE-2017-17817.
How can I fix CVE-2017-17817?
To fix CVE-2017-17817, update Netwide Assembler (NASM) to version 2.13.02 or higher.
Where can I find more information about CVE-2017-17817?
You can find more information about CVE-2017-17817 on the following references: [Bugzilla](https://bugzilla.nasm.us/show_bug.cgi?id=3392427), [Ubuntu Security Notice](https://usn.ubuntu.com/3694-1/), [Launchpad](https://launchpad.net/bugs/cve/CVE-2017-17817)