PT-2018-9602 · Netwide Assembler+1 · Nasm+1

Situlingyun

·

Publicado

2018-12-20

·

Atualizado

2019-02-01

·

CVE-2018-1000886

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: nasm versions 2.14.01rc5 through 2.15
Description: The issue is related to a Buffer Overflow in the asm/stdscan.c file at line 130, which can cause a stack-overflow due to endless macro generation when triggered by a crafted nasm input file, leading to a program crash.
Recommendations: For nasm versions 2.14.01rc5 through 2.15, consider disabling the macro generation feature as a temporary workaround until a patch is available. Restrict access to the asm/stdscan.c file to minimize the risk of exploitation. Avoid using crafted nasm input files that can trigger the endless macro generation.

Exploit

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1000886

Produtos afetados

Debian
Nasm