PT-2004-1043 · Debian+2 · Debian+2
Published
2004-12-22
·
Updated
2023-12-22
·
CVE-2004-1287
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
nasm version 0.98.38
nasm version 1.2
Debian GNU/Linux nasm (affected versions not specified)
Description
The issue is related to a buffer overflow in the error function in preproc.c for nasm, which allows attackers to execute arbitrary code via a crafted asm file. Multiple vulnerabilities in the nasm package of the Debian GNU/Linux operating system can lead to violations of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations
For nasm version 0.98.38, update to a version that fixes the buffer overflow issue in preproc.c.
For nasm version 1.2, apply the necessary patches or updates to address the buffer overflow vulnerability.
For Debian GNU/Linux nasm, apply the available security updates for the nasm package to mitigate the multiple vulnerabilities.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Red Hat
Nasm