First published: Fri Dec 28 2018(Updated: )
There is a use-after-free at asm/preproc.c (function pp_getline) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service during certain finishes tests.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nasm Netwide Assembler | =2.14.0-rc16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20538 is a vulnerability in Netwide Assembler (NASM) 2.14rc1 that allows an attacker to cause a denial of service through a use-after-free vulnerability in the pp_getline function in asm/preproc.c.
The severity of CVE-2018-20538 is medium with a CVSS score of 5.5.
CVE-2018-20538 affects Netwide Assembler (NASM) version 2.14rc16.
An attacker can exploit CVE-2018-20538 by causing a denial of service during certain finish tests.
Yes, upgrading to a version of Netwide Assembler (NASM) higher than or equal to 2.14.0-rc16 resolves the vulnerability.