PT-2018-9788 · Netwide+1 · Netwide Assembler+1
Trace Probe
·
Published
2018-04-21
·
Updated
2020-07-31
·
CVE-2018-10254
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Netwide Assembler (NASM) version 2.13
Description:
The issue is a stack-based buffer over-read in the
disasm function of the disasm/disasm.c file. This could allow remote attackers to cause a denial of service or possibly have other unspecified impacts by using a crafted ELF file.Recommendations:
For Netwide Assembler (NASM) version 2.13, consider avoiding the use of crafted ELF files until a patch is available. As a temporary workaround, restrict access to the
disasm function to minimize the risk of exploitation.Exploit
Fix
DoS
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netwide Assembler
Suse