CVE-2018-19214: High severity nasm Netwide Assembler vulnerability
Published Nov 12, 2018
·Updated
Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expandmmacparams in asm/preproc.c for insufficient input.
Affected Software
4 affected components
nasm Netwide Assembler=12.14-rc15
redhat Enterprise Linux=5.0
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
Remediation
Event History
Nov 12, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2018-19214.
2
What is the severity of CVE-2018-19214?
The severity of CVE-2018-19214 is high (7.8).
3
What is the affected software for CVE-2018-19214?
The affected software for CVE-2018-19214 includes Netwide Assembler (NASM) 2.14rc15 and Redhat Enterprise Linux (versions 5.0, 6.0, 7.0).
4
What is the description of CVE-2018-19214?
CVE-2018-19214 is a heap-based buffer over-read vulnerability in the expand_mmac_params function in asm/preproc.c in Netwide Assembler (NASM) 2.14rc15.
5
How can I fix CVE-2018-19214?
To fix CVE-2018-19214, it is recommended to upgrade to a patched version of Netwide Assembler (NASM) or apply the necessary security updates for Redhat Enterprise Linux.