PT-2018-9788 · Netwide+1 · Netwide Assembler+1

Trace Probe

·

Published

2018-04-21

·

Updated

2020-07-31

·

CVE-2018-10254

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Netwide Assembler (NASM) version 2.13
Description: The issue is a stack-based buffer over-read in the disasm function of the disasm/disasm.c file. This could allow remote attackers to cause a denial of service or possibly have other unspecified impacts by using a crafted ELF file.
Recommendations: For Netwide Assembler (NASM) version 2.13, consider avoiding the use of crafted ELF files until a patch is available. As a temporary workaround, restrict access to the disasm function to minimize the risk of exploitation.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10254
MGASA-2020-0303
OPENSUSE-SU-2020:0952-1
OPENSUSE-SU-2020:0954-1
OPENSUSE-SU-2020_0952-1
OPENSUSE-SU-2020_0954-1
SUSE-SU-2020:1843-1

Affected Products

Netwide Assembler
Suse