PT-2023-22321 · Yasm+1 · Yasm+1

Z1R00

·

Published

2023-04-12

·

Updated

2024-08-02

·

CVE-2023-29581

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions yasm version 1.3.0.55.g101bc
Description The issue is related to a segmentation violation in the delete Token function at modules/preprocs/nasm/nasm-pp.c. Although this could potentially make a libyasm application unavailable if exploited, the vendor considers it to have no security relevance due to expected input validation or sandboxing.
Recommendations For yasm version 1.3.0.55.g101bc, consider applying input validation before data reaches libyasm or ensure the application runs in a sandbox to minimize potential impact. As a temporary workaround, consider restricting access to the delete Token function until a more permanent solution is available.

Exploit

Fix

Related Identifiers

AZL-26166
AZL-35387
CVE-2023-29581

Affected Products

Debian
Yasm