CVE-2018-1000667
published 2018-09-06CVE-2018-1000667: NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory corruption (crashed) of nasm when handling a crafted file due to function…
PriorityP423medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.23%
65.3th percentile
NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory corruption (crashed) of nasm when handling a crafted file due to function assemble_file(inname, depend_ptr) at asm/nasm.c:482. vulnerability in function assemble_file(inname, depend_ptr) at asm/nasm.c:482. that can result in aborting/crash nasm program. This attack appear to be exploitable via a specially crafted asm file..
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nasm | < nasm 2.14-1 (bookworm) | nasm 2.14-1 (bookworm) |
| nasm | nasm | >= 0 < 2.14-1 | 2.14-1 |
| nasm | nasm | >= 0 < 2.14-1 | 2.14-1 |
| nasm | nasm | >= 0 < 2.14-1 | 2.14-1 |
| nasm | nasm | >= 0 < 2.14-1 | 2.14-1 |
| nasm | netwide_assembler | <= 2.14.0 | — |
| nasm | netwide_assembler | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
nasm: Memory corruption in assemble_file() function in asm/nasm.c:482
vendor_redhat·2018-09-06·CVSS 5.5
CVE-2018-1000667 [MEDIUM] CWE-119 nasm: Memory corruption in assemble_file() function in asm/nasm.c:482
nasm: Memory corruption in assemble_file() function in asm/nasm.c:482
NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory corruption (crashed) of nasm when handling a crafted file due to function assemble_file(inname, depend_ptr) at asm/nasm.c:482. vulnerability in function assemble_file(inname, depend_ptr) at asm/nasm.c:482. that can result in aborting/crash nasm program. This attack appear to be exploitable via a specially crafted asm file..
Package: nasm (Red Hat Enterprise Linux 5) - Not affected
Package: nasm (Red Hat Enterprise Linux 6) - Will not fix
Package: nasm (Red Hat Enterprise Linux 7) - Fix deferred
Package: nasm (Red Hat Enterprise Linux 8) - Will not fix
Debian
CVE-2018-1000667: nasm - NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory ...
vendor_debian·2018·CVSS 5.5
CVE-2018-1000667 [MEDIUM] CVE-2018-1000667: nasm - NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory ...
NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory corruption (crashed) of nasm when handling a crafted file due to function assemble_file(inname, depend_ptr) at asm/nasm.c:482. vulnerability in function assemble_file(inname, depend_ptr) at asm/nasm.c:482. that can result in aborting/crash nasm program. This attack appear to be exploitable via a specially crafted asm file..
Scope: local
bookworm: resolved (fixed in 2.14-1)
bullseye: resolved (fixed in 2.14-1)
forky: resolved (fixed in 2.14-1)
sid: resolved (fixed in 2.14-1)
trixie: resolved (fixed in 2.14-1)
GHSA
GHSA-mx2f-ggfx-v955: NASM nasm-2
ghsa_unreviewed·2022-05-13
CVE-2018-1000667 [MEDIUM] CWE-119 GHSA-mx2f-ggfx-v955: NASM nasm-2
NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory corruption (crashed) of nasm when handling a crafted file due to function assemble_file(inname, depend_ptr) at asm/nasm.c:482. vulnerability in function assemble_file(inname, depend_ptr) at asm/nasm.c:482. that can result in aborting/crash nasm program. This attack appear to be exploitable via a specially crafted asm file..
OSV
CVE-2018-1000667: NASM nasm-2
osv·2018-09-06·CVSS 5.5
CVE-2018-1000667 [MEDIUM] CVE-2018-1000667: NASM nasm-2
NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory corruption (crashed) of nasm when handling a crafted file due to function assemble_file(inname, depend_ptr) at asm/nasm.c:482. vulnerability in function assemble_file(inname, depend_ptr) at asm/nasm.c:482. that can result in aborting/crash nasm program. This attack appear to be exploitable via a specially crafted asm file..
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1000667 nasm: Memory corruption in assemble_file() function in asm/nasm.c:482 [fedora-all]
bugzilla·2018-09-06·CVSS 5.5
CVE-2018-1000667 [MEDIUM] CVE-2018-1000667 nasm: Memory corruption in assemble_file() function in asm/nasm.c:482 [fedora-all]
CVE-2018-1000667 nasm: Memory corruption in assemble_file() function in asm/nasm.c:482 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2018-1000667 nasm: Memory corruption in assemble_file() function in asm/nasm.c:482
bugzilla·2018-09-06·CVSS 5.5
CVE-2018-1000667 [MEDIUM] CVE-2018-1000667 nasm: Memory corruption in assemble_file() function in asm/nasm.c:482
CVE-2018-1000667 nasm: Memory corruption in assemble_file() function in asm/nasm.c:482
NASM 2.10.07 through 2.13.03, and potentially earlier, contains a denial of service vulnerability that can result in a segmentation fault due to the program incorrectly dereferencing an invalid address. This attack is exploitable via a specially crafted asm file.
Upstream bug:
https://bugzilla.nasm.us/show_bug.cgi?id=3392507
References:
https://github.com/cyrillos/nasm/issues/3
Discussion:
Created nasm tracking bugs for this issue:
Affects: fedora-all [bug 1626257]
---
Posted analysis upstream, copying here. In summary, found a new, very similar crash.
This appears to be due to the following pattern in preproc.c:
```c
tt = tokenize(tline->text);
tt = expand_smacro(tt);
size = parse_size(tt->t
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00017.htmlhttps://bugzilla.nasm.us/show_bug.cgi?id=3392507https://github.com/cyrillos/nasm/issues/3http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00017.htmlhttps://bugzilla.nasm.us/show_bug.cgi?id=3392507https://github.com/cyrillos/nasm/issues/3
2018-09-06
Published