First published: Mon Sep 03 2018(Updated: )
Netwide Assembler (NASM) 2.14rc15 has a buffer over-read in x86/regflags.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nasm Netwide Assembler | =2.14-rc15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16382 is a vulnerability in Netwide Assembler (NASM) 2.14rc15 that allows for a buffer over-read in x86/regflags.c.
CVE-2018-16382 has a severity level of medium, with a severity value of 5.5.
CVE-2018-16382 could allow an attacker to perform a buffer over-read in x86/regflags.c, potentially leading to information disclosure or denial of service.
Yes, a fix for CVE-2018-16382 is available. It is recommended to update Netwide Assembler (NASM) to version 2.14rc16 or later.
More information about CVE-2018-16382 can be found in the references: http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00015.html, http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00017.html, and https://bugzilla.nasm.us/show_bug.cgi?id=3392503.