First published: Fri Dec 28 2018(Updated: )
There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service during a line-number increment attempt.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nasm Netwide Assembler | =2.14.0-rc16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-20535.
The affected software is Netwide Assembler (NASM) version 2.14rc16.
The severity of CVE-2018-20535 is medium with a CVSS score of 5.5.
The use-after-free vulnerability can be exploited by causing a denial of service during a line-number increment attempt.
Yes, a fix is available for CVE-2018-20535. It is recommended to update to a version of Netwide Assembler (NASM) that is not affected by this vulnerability.