CVE-2017-17818: High severity nasm Netwide Assembler vulnerability
In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read that will cause a remote denial of service attack, related to a while loop in pastetokens in asm/preproc.c.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/nasmto a version that resolves this vulnerability.Fixed in 2.15.05-1Fixed in 2.16.01-1Fixed in 2.16.03-1Fixed in 3.01-1
Event History
Frequently Asked Questions
What is CVE-2017-17818?
CVE-2017-17818 is a vulnerability in Netwide Assembler (NASM) 2.14rc0 that allows for a heap-based buffer over-read, leading to a remote denial of service attack.
How can the heap-based buffer over-read in NASM be exploited?
The vulnerability can be exploited by an attacker to cause a denial of service by sending specially crafted input to the affected system.
What is the severity of CVE-2017-17818?
CVE-2017-17818 has a severity rating of high with a CVSS score of 7.5.
Which versions of NASM are affected by CVE-2017-17818?
NASM versions 2.14rc0 and earlier are affected by CVE-2017-17818.
How can I mitigate the vulnerability in NASM?
To mitigate the vulnerability, it is recommended to update NASM to version 2.14 or later.