PT-2023-5264 · Netwide Assembler+3 · Nasm+3
Naihsin
·
Published
2023-08-22
·
Updated
2024-12-08
·
CVE-2022-29654
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
nasm versions prior to 2.15.05
Description
The issue is related to a buffer overflow vulnerability in the
quote for pmake function in asm/nasm.c of the Netwide Assembler (NASM). This vulnerability can be exploited by attackers to cause a denial of service via crafted files. The vulnerability is associated with the lack of size checking for input data, allowing for uncontrolled copying into a buffer.Recommendations
For versions prior to 2.15.05, update to version 2.15.05 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
quote for pmake function in asm/nasm.c to minimize the risk of exploitation.Exploit
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Red Os
Nasm