CVE-2018-10254: High severity netwide assembler (nasm) vulnerability
Published Apr 21, 2018
·Updated
Netwide Assembler (NASM) 2.13 has a stack-based buffer over-read in the disasm function of the disasm/disasm.c file. Remote attackers could leverage this vulnerability to cause a denial of service or possibly have unspecified other impact via a crafted ELF file.
Affected Software
1 affected component
nasm Netwide Assembler=2.13
Event History
Apr 21, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-10254.
2
What is the severity of CVE-2018-10254?
The severity of CVE-2018-10254 is high with a CVSS score of 7.8.
3
What is the affected software?
The affected software is the Netwide Assembler (NASM) version 2.13.
4
What is the impact of the vulnerability?
The vulnerability could cause a denial of service or potentially have other unspecified impacts.
5
Is there a fix available for CVE-2018-10254?
Yes, please refer to the provided references for patches or updates to address this vulnerability.