CVE-2017-17820: Use After Free
Published Dec 21, 2017
·Updated
In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pplistonemacro in asm/preproc.c that will lead to a remote denial of service attack, related to mishandling of operand-type errors.
Affected Software
3 affected componentsFixes available
nasm Netwide Assembler=2.14-rc0
Canonical Ubuntu Linux=14.04
debian/nasm
2.15.05-12.16.01-12.16.03-13.01-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/nasmto a version that resolves this vulnerability.Fixed in 2.15.05-1Fixed in 2.16.01-1Fixed in 2.16.03-1Fixed in 3.01-1
Event History
Dec 21, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Data Sourced
via NVD·03:29 AM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:34 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·08:00 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·08:01 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2017-17820.
2
What is the severity rating of CVE-2017-17820?
The severity rating of CVE-2017-17820 is 5.5 (Medium).
3
How does the vulnerability in NASM 2.14rc0 manifest?
The vulnerability manifests as a use-after-free in the pp_list_one_macro function in asm/preproc.c.
4
What is the impact of this vulnerability?
The vulnerability can lead to a remote denial of service attack.
5
How can I fix the vulnerability in NASM 2.14rc0?
To fix the vulnerability, update NASM to version 2.13.02 or later.