CVE-2018-20535: Use After Free
Published Dec 28, 2018
·Updated
There is a use-after-free at asm/preproc.c (function ppgetline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service during a line-number increment attempt.
Affected Software
1 affected component
nasm Netwide Assembler=2.14.0-rc16
Event History
Dec 28, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this use-after-free vulnerability?
The vulnerability ID is CVE-2018-20535.
2
What is the affected software?
The affected software is Netwide Assembler (NASM) version 2.14rc16.
3
What is the severity of CVE-2018-20535?
The severity of CVE-2018-20535 is medium with a CVSS score of 5.5.
4
How can the use-after-free vulnerability be exploited?
The use-after-free vulnerability can be exploited by causing a denial of service during a line-number increment attempt.
5
Is there a fix available for CVE-2018-20535?
Yes, a fix is available for CVE-2018-20535. It is recommended to update to a version of Netwide Assembler (NASM) that is not affected by this vulnerability.