CVE-2020-18780: Use After Free
Published Aug 22, 2023
·Updated
A Use After Free vulnerability in function newToken in asm/preproc.c in nasm 2.14.02 allows attackers to cause a denial of service via crafted nasm command.
Affected Software
1 affected component
nasm Netwide Assembler=2.14.02
Event History
Aug 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-18780?
The severity of CVE-2020-18780 is medium with a CVSS score of 5.5.
2
What is the impacted software for CVE-2020-18780?
The impacted software for CVE-2020-18780 is Nasm Netwide Assembler version 2.14.02.
3
How does CVE-2020-18780 allow attackers to cause a denial of service?
CVE-2020-18780 allows attackers to cause a denial of service by exploiting a Use After Free vulnerability in the new_Token function.
4
How can I mitigate the CVE-2020-18780 vulnerability?
To mitigate the CVE-2020-18780 vulnerability, update the Nasm Netwide Assembler software to version 2.14.03 or higher.
5
Where can I find more information about CVE-2020-18780?
More information about CVE-2020-18780 can be found in the bugzilla.nasm.us link: https://bugzilla.nasm.us/show_bug.cgi?id=3392634