PT-2018-9602 · Netwide Assembler+1 · Nasm+1
Situlingyun
·
Published
2018-12-20
·
Updated
2019-02-01
·
CVE-2018-1000886
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
nasm versions 2.14.01rc5 through 2.15
Description:
The issue is related to a Buffer Overflow in the
asm/stdscan.c file at line 130, which can cause a stack-overflow due to endless macro generation when triggered by a crafted nasm input file, leading to a program crash.Recommendations:
For nasm versions 2.14.01rc5 through 2.15, consider disabling the macro generation feature as a temporary workaround until a patch is available. Restrict access to the
asm/stdscan.c file to minimize the risk of exploitation. Avoid using crafted nasm input files that can trigger the endless macro generation.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Nasm