First published: Thu Dec 21 2017(Updated: )
In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read that will cause a remote denial of service attack, related to a while loop in paste_tokens in asm/preproc.c.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nasm Netwide Assembler | =2.14-rc0 | |
Canonical Ubuntu Linux | =14.04 | |
debian/nasm | 2.15.05-1 2.16.01-1 2.16.03-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17818 is a vulnerability in Netwide Assembler (NASM) 2.14rc0 that allows for a heap-based buffer over-read, leading to a remote denial of service attack.
The vulnerability can be exploited by an attacker to cause a denial of service by sending specially crafted input to the affected system.
CVE-2017-17818 has a severity rating of high with a CVSS score of 7.5.
NASM versions 2.14rc0 and earlier are affected by CVE-2017-17818.
To mitigate the vulnerability, it is recommended to update NASM to version 2.14 or later.