PT-2004-1043 · Debian+2 · Debian+2

Published

2004-12-22

·

Updated

2023-12-22

·

CVE-2004-1287

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions nasm version 0.98.38 nasm version 1.2 Debian GNU/Linux nasm (affected versions not specified)
Description The issue is related to a buffer overflow in the error function in preproc.c for nasm, which allows attackers to execute arbitrary code via a crafted asm file. Multiple vulnerabilities in the nasm package of the Debian GNU/Linux operating system can lead to violations of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations For nasm version 0.98.38, update to a version that fixes the buffer overflow issue in preproc.c. For nasm version 1.2, apply the necessary patches or updates to address the buffer overflow vulnerability. For Debian GNU/Linux nasm, apply the available security updates for the nasm package to mitigate the multiple vulnerabilities.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2015-04097
CVE-2004-1287
DSA-623-1
RHSA-2005:381
RHSA-2005_381

Affected Products

Debian
Red Hat
Nasm