CVE-2019-14248: Null Pointer Dereference
In libnasm.a in Netwide Assembler (NASM) 2.14.xx, asm/pragma.c allows a NULL pointer dereference in processpragma, searchpragmalist, and nasmsetlimit when "%pragma limit" is mishandled.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-14248?
CVE-2019-14248 is a vulnerability in the Netwide Assembler (NASM) 2.14.xx that allows a NULL pointer dereference in certain functions, leading to a crash or potential code execution.
How severe is CVE-2019-14248?
CVE-2019-14248 has a severity score of 5.5, which is considered medium severity.
What is the affected software?
The affected software is Netwide Assembler (NASM) 2.14.xx.
How can the vulnerability be exploited?
The vulnerability can be exploited by mishandling the "%pragma limit" directive in certain functions in NASM.
Is there a fix available for CVE-2019-14248?
Yes, a fix for CVE-2019-14248 is available. It is recommended to update to a version of NASM that is not affected by this vulnerability.