PT-2018-9602 · Netwide Assembler+1 · Nasm+1

Situlingyun

·

Published

2018-12-20

·

Updated

2019-02-01

·

CVE-2018-1000886

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: nasm versions 2.14.01rc5 through 2.15
Description: The issue is related to a Buffer Overflow in the asm/stdscan.c file at line 130, which can cause a stack-overflow due to endless macro generation when triggered by a crafted nasm input file, leading to a program crash.
Recommendations: For nasm versions 2.14.01rc5 through 2.15, consider disabling the macro generation feature as a temporary workaround until a patch is available. Restrict access to the asm/stdscan.c file to minimize the risk of exploitation. Avoid using crafted nasm input files that can trigger the endless macro generation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1000886

Affected Products

Debian
Nasm