First published: Mon Nov 12 2018(Updated: )
Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nasm Netwide Assembler | =12.14-rc15 | |
Redhat Enterprise Linux | =5.0 | |
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-19214.
The severity of CVE-2018-19214 is high (7.8).
The affected software for CVE-2018-19214 includes Netwide Assembler (NASM) 2.14rc15 and Redhat Enterprise Linux (versions 5.0, 6.0, 7.0).
CVE-2018-19214 is a heap-based buffer over-read vulnerability in the expand_mmac_params function in asm/preproc.c in Netwide Assembler (NASM) 2.14rc15.
To fix CVE-2018-19214, it is recommended to upgrade to a patched version of Netwide Assembler (NASM) or apply the necessary security updates for Redhat Enterprise Linux.