CVE-2018-8883: High severity nasm Netwide Assembler vulnerability
Netwide Assembler (NASM) 2.13.02rc2 has a buffer over-read in the parseline function in asm/parser.c via uncontrolled access to nasmregflags.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-8883?
CVE-2018-8883 is a vulnerability in Netwide Assembler (NASM) 2.13.02rc2 that allows uncontrolled access to nasm_reg_flags, leading to a buffer over-read in the parse_line function in asm/parser.c.
How severe is CVE-2018-8883?
CVE-2018-8883 has a severity rating of 7.8 (high).
Which version of Netwide Assembler (NASM) is affected by CVE-2018-8883?
The affected version of Netwide Assembler (NASM) is 2.13.02rc2.
How can I fix CVE-2018-8883?
To fix CVE-2018-8883, it is recommended to update Netwide Assembler (NASM) to a version that does not have the vulnerability.
Where can I find more information about CVE-2018-8883?
You can find more information about CVE-2018-8883 in the following references: [Reference 1](http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00015.html), [Reference 2](http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00017.html), [Reference 3](https://bugzilla.nasm.us/show_bug.cgi?id=3392447).