First published: Tue Mar 20 2018(Updated: )
Netwide Assembler (NASM) 2.13.02rc2 has a buffer over-read in the parse_line function in asm/parser.c via uncontrolled access to nasm_reg_flags.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nasm Netwide Assembler | =2.13.02-rc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8883 is a vulnerability in Netwide Assembler (NASM) 2.13.02rc2 that allows uncontrolled access to nasm_reg_flags, leading to a buffer over-read in the parse_line function in asm/parser.c.
CVE-2018-8883 has a severity rating of 7.8 (high).
The affected version of Netwide Assembler (NASM) is 2.13.02rc2.
To fix CVE-2018-8883, it is recommended to update Netwide Assembler (NASM) to a version that does not have the vulnerability.
You can find more information about CVE-2018-8883 in the following references: [Reference 1](http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00015.html), [Reference 2](http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00017.html), [Reference 3](https://bugzilla.nasm.us/show_bug.cgi?id=3392447).