First published: Thu Dec 21 2017(Updated: )
In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_list_one_macro in asm/preproc.c that will lead to a remote denial of service attack, related to mishandling of operand-type errors.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nasm Netwide Assembler | =2.14-rc0 | |
Canonical Ubuntu Linux | =14.04 | |
debian/nasm | 2.15.05-1 2.16.01-1 2.16.03-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2017-17820.
The severity rating of CVE-2017-17820 is 5.5 (Medium).
The vulnerability manifests as a use-after-free in the pp_list_one_macro function in asm/preproc.c.
The vulnerability can lead to a remote denial of service attack.
To fix the vulnerability, update NASM to version 2.13.02 or later.