First published: Mon Jan 06 2020(Updated: )
In Netwide Assembler (NASM) 2.15rc0, a heap-based buffer over-read occurs (via a crafted .asm file) in set_text_free when called from expand_one_smacro in asm/preproc.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nasm Netwide Assembler | =2.15-rc0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-20352 is a vulnerability in Netwide Assembler (NASM) 2.15rc0 that allows for a heap-based buffer over-read when a crafted .asm file is processed.
The vulnerability occurs in the set_text_free function when called from expand_one_smacro in asm/preproc.c.
Netwide Assembler (NASM) version 2.15rc0 is affected by the vulnerability.
The severity of CVE-2019-20352 is high, with a severity value of 7.1.
Upgrading to a version of Netwide Assembler (NASM) that is not affected by the vulnerability, such as a version later than 2.15rc0, is recommended to fix the issue.