PT-2018-18689 · Netwide+1 · Netwide Assembler+1
Jun
·
Published
2018-03-20
·
Updated
2020-07-13
·
CVE-2018-8883
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Netwide Assembler (NASM) version 2.13.02rc2
Description
The issue is related to a buffer over-read in the parse line function, located in asm/parser.c. This occurs due to uncontrolled access to
nasm reg flags.Recommendations
For Netwide Assembler (NASM) version 2.13.02rc2, consider restricting access to the parse line function in asm/parser.c until a patch is available. As a temporary workaround, avoid using the
nasm reg flags variable in the affected function to minimize the risk of exploitation.Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netwide Assembler
Suse