First published: Thu Sep 06 2018(Updated: )
NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory corruption (crashed) of nasm when handling a crafted file due to function assemble_file(inname, depend_ptr) at asm/nasm.c:482. vulnerability in function assemble_file(inname, depend_ptr) at asm/nasm.c:482. that can result in aborting/crash nasm program. This attack appear to be exploitable via a specially crafted asm file..
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nasm Netwide Assembler | <=2.14.0 | |
Nasm Netwide Assembler | =2.14.0-rc1 | |
Nasm Netwide Assembler | =2.14.0-rc10 | |
Nasm Netwide Assembler | =2.14.0-rc11 | |
Nasm Netwide Assembler | =2.14.0-rc12 | |
Nasm Netwide Assembler | =2.14.0-rc13 | |
Nasm Netwide Assembler | =2.14.0-rc14 | |
Nasm Netwide Assembler | =2.14.0-rc15 | |
Nasm Netwide Assembler | =2.14.0-rc2 | |
Nasm Netwide Assembler | =2.14.0-rc3 | |
Nasm Netwide Assembler | =2.14.0-rc4 | |
Nasm Netwide Assembler | =2.14.0-rc5 | |
Nasm Netwide Assembler | =2.14.0-rc6 | |
Nasm Netwide Assembler | =2.14.0-rc7 | |
Nasm Netwide Assembler | =2.14.0-rc8 | |
Nasm Netwide Assembler | =2.14.0-rc9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1000667 is medium with a CVSS score of 5.5.
Versions 2.14.0-rc1 to 2.14.0-rc15 of Nasm Netwide Assembler are affected by CVE-2018-1000667.
CVE-2018-1000667 can lead to memory corruption and crashes in Nasm Netwide Assembler when handling a crafted file.
Yes, you can refer to the references listed to find the fixes for CVE-2018-1000667.
You can find more information about CVE-2018-1000667 in the references provided.