CVE-2019-20352: High severity netwide assembler (nasm) vulnerability
Published Jan 6, 2020
·Updated
In Netwide Assembler (NASM) 2.15rc0, a heap-based buffer over-read occurs (via a crafted .asm file) in settextfree when called from expandonesmacro in asm/preproc.c.
Affected Software
1 affected component
nasm Netwide Assembler=2.15-rc0
Event History
Jan 6, 2020
CVE Published
via MITRE·05:05 AM
Data Sourced
via MITRE·05:05 AM
Description
Sep 4, 2025
Data Sourced
via Microsoft·12:19 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2019-20352?
CVE-2019-20352 is a vulnerability in Netwide Assembler (NASM) 2.15rc0 that allows for a heap-based buffer over-read when a crafted .asm file is processed.
2
How does the vulnerability occur?
The vulnerability occurs in the set_text_free function when called from expand_one_smacro in asm/preproc.c.
3
Which software versions are affected by CVE-2019-20352?
Netwide Assembler (NASM) version 2.15rc0 is affected by the vulnerability.
4
What is the severity of CVE-2019-20352?
The severity of CVE-2019-20352 is high, with a severity value of 7.1.
5
How can I fix the vulnerability?
Upgrading to a version of Netwide Assembler (NASM) that is not affected by the vulnerability, such as a version later than 2.15rc0, is recommended to fix the issue.