CVE-2018-19755: Input Validation
Published Nov 30, 2018
·Updated
There is an illegal address access at asm/preproc.c (function: ismmacro) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service (out-of-bounds array access) because a certain conversion can result in a negative integer.
Affected Software
1 affected component
nasm Netwide Assembler=12.14-rc16
Event History
Nov 30, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-19755.
2
What is the severity level of CVE-2018-19755?
The severity level of CVE-2018-19755 is medium.
3
What is the affected software for CVE-2018-19755?
The affected software for CVE-2018-19755 is Netwide Assembler (NASM) 2.14rc16.
4
What is the cause of the vulnerability in CVE-2018-19755?
The vulnerability in CVE-2018-19755 is caused by an illegal address access in the is_mmacro function in asm/preproc.c of Netwide Assembler (NASM) 2.14rc16.
5
How can the vulnerability in CVE-2018-19755 be exploited?
The vulnerability in CVE-2018-19755 can be exploited by causing a denial of service through out-of-bounds array access.