CVE-2017-10686
published 2017-06-29CVE-2017-10686: In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token()…
PriorityP339high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
2.95%
85.6th percentile
In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function (called by pp_getline()) - it is used again at multiple positions later that could cause multiple damages. For example, it causes a corrupted double-linked list in detoken(), a double free or corruption in delete_Token(), and an out-of-bounds write in detoken(). It has a high possibility to lead to a remote code execution attack.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | nasm | < nasm 2.13.02-0.1 (bookworm) | nasm 2.13.02-0.1 (bookworm) |
| nasm | nasm | >= 0 < 2.13.02-0.1 | 2.13.02-0.1 |
| nasm | nasm | >= 0 < 2.13.02-0.1 | 2.13.02-0.1 |
| nasm | nasm | >= 0 < 2.13.02-0.1 | 2.13.02-0.1 |
| nasm | nasm | >= 0 < 2.13.02-0.1 | 2.13.02-0.1 |
| nasm | netwide_assembler | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
nasm: use-after-free in detoken at asm/preproc.c
vendor_redhat·2018-08-28·CVSS 7.8
CVE-2018-19216 [HIGH] CWE-416 nasm: use-after-free in detoken at asm/preproc.c
nasm: use-after-free in detoken at asm/preproc.c
Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c.
Statement: This flaw was found to be a duplicate of CVE-2017-10686. Please see https://access.redhat.com/security/cve/CVE-2017-10686 for information about affected products and security errata.
Package: nasm (Red Hat Enterprise Linux 5) - Not affected
Package: nasm (Red Hat Enterprise Linux 6) - Not affected
Package: nasm (Red Hat Enterprise Linux 7) - Not affected
Package: nasm (Red Hat Enterprise Linux 8) - Not affected
Ubuntu
NASM vulnerabilities
vendor_ubuntu·2018-06-28
CVE-2017-10686 NASM vulnerabilities
Title: NASM vulnerabilities
Summary: NASM could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that NASM incorrectly handled certain source files. If a
user or automated system were tricked into processing a specially crafted
source file, a remote attacker could use these issues to cause NASM to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
nasm: Use-after-free in the detoken() function
vendor_redhat·2017-06-24·CVSS 7.8
CVE-2017-10686 [HIGH] CWE-416 nasm: Use-after-free in the detoken() function
nasm: Use-after-free in the detoken() function
In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function (called by pp_getline()) - it is used again at multiple positions later that could cause multiple damages. For example, it causes a corrupted double-linked list in detoken(), a double free or corruption in delete_Token(), and an out-of-bounds write in detoken(). It has a high possibility to lead to a remote code execution attack.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity
Debian
CVE-2017-10686: nasm - In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vuln...
vendor_debian·2017·CVSS 7.8
CVE-2017-10686 [HIGH] CVE-2017-10686: nasm - In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vuln...
In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function (called by pp_getline()) - it is used again at multiple positions later that could cause multiple damages. For example, it causes a corrupted double-linked list in detoken(), a double free or corruption in delete_Token(), and an out-of-bounds write in detoken(). It has a high possibility to lead to a remote code execution attack.
Scope: local
bookworm: resolved (fixed in 2.13.02-0.1)
bullseye: resolved (fixed in 2.13.02-0.1)
forky: resolved (fixed in 2.13.02-0.1)
sid: resolved (fixed in 2.13.02-0.1)
trixie: resolved (fixed in 2.13.02-0.1)
GHSA
GHSA-vppv-9vcp-9fcg: In Netwide Assembler (NASM) 2
ghsa_unreviewed·2022-05-14
CVE-2017-10686 [HIGH] CWE-416 GHSA-vppv-9vcp-9fcg: In Netwide Assembler (NASM) 2
In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function (called by pp_getline()) - it is used again at multiple positions later that could cause multiple damages. For example, it causes a corrupted double-linked list in detoken(), a double free or corruption in delete_Token(), and an out-of-bounds write in detoken(). It has a high possibility to lead to a remote code execution attack.
OSV
CVE-2017-10686: In Netwide Assembler (NASM) 2
osv·2017-06-29·CVSS 7.8
CVE-2017-10686 [HIGH] CVE-2017-10686: In Netwide Assembler (NASM) 2
In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function (called by pp_getline()) - it is used again at multiple positions later that could cause multiple damages. For example, it causes a corrupted double-linked list in detoken(), a double free or corruption in delete_Token(), and an out-of-bounds write in detoken(). It has a high possibility to lead to a remote code execution attack.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-19216 nasm: use-after-free in detoken at asm/preproc.c
bugzilla·2018-11-21·CVSS 7.8
CVE-2018-19216 [HIGH] CVE-2018-19216 nasm: use-after-free in detoken at asm/preproc.c
CVE-2018-19216 nasm: use-after-free in detoken at asm/preproc.c
A flaw was found in Netwide Assembler (NASM) before 2.13.02. A use-after-free in detoken at asm/preproc.c.
References:
https://bugzilla.nasm.us/show_bug.cgi?id=3392425
Upstream Patch:
https://repo.or.cz/nasm.git/commit/4b5b737d4991578b1918303dc0fd9c9ab5c7ce4f
Discussion:
Created nasm tracking bugs for this issue:
Affects: fedora-all [bug 1652047]
---
*** This bug has been marked as a duplicate of bug 1472882 ***
---
Statement:
This flaw was found to be a duplicate of CVE-2017-10686. Please see https://access.redhat.com/security/cve/CVE-2017-10686 for information about affected products and security errata.
Bugzilla
CVE-2017-10686 nasm: Use-after-free in the detoken() function
bugzilla·2017-07-19·CVSS 7.8
CVE-2017-10686 [HIGH] CVE-2017-10686 nasm: Use-after-free in the detoken() function
CVE-2017-10686 nasm: Use-after-free in the detoken() function
In Netwide Assembler (NASM), there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function (called by pp_getline()) - it is used again at multiple positions later that could cause multiple damages. For example, it causes a corrupted double-linked list in detoken(), a double free or corruption in delete_Token(), and an out-of-bounds write in detoken().
Upstream issue:
https://bugzilla.nasm.us/show_bug.cgi?id=3392414
Discussion:
Created nasm tracking bugs for this issue:
Affects: fedora-all [bug 1472885]
---
Patch:
http://repo.or.cz/nasm.git/commit/736be08cf3ec4d1da31f350359feb8c1c782de9a
http://repo.or.cz/nasm.git/commit/f
Bugzilla
CVE-2017-10686 CVE-2017-11111 nasm: various flaws [fedora-all]
bugzilla·2017-07-19·CVSS 7.8
CVE-2017-10686 [HIGH] CVE-2017-10686 CVE-2017-11111 nasm: various flaws [fedora-all]
CVE-2017-10686 CVE-2017-11111 nasm: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whi
arXiv
Binary-level Directed Fuzzing for Use-After-Free Vulnerabilities
arxiv_fulltext·2020-08-17
Binary-level Directed Fuzzing for Use-After-Free Vulnerabilities
-2emBinary-level Directed Fuzzing for Use-After-Free Vulnerabilities
## Abstract
Directed fuzzing focuses on automatically testing specific parts of the code by taking advantage of additional information such as (partial) bug stack trace, patches
or risky operations. Key applications include bug reproduction, patch testing and static analysis report verification. Although directed fuzzing has received
a lot of attention recently,
hard-to-detect vulnerabilities such as Use-After-Free ( ) are still not well
addressed,
especially at the binary level.
We propose , the first (binary-level) directed greybox fuzzer dedicated to
\ bugs.
The technique features a fuzzing engine tailored to \ specifics, a lightweight code instrumentation and an efficient bug triage step.
Experimental evaluation f
2017-06-29
Published