CVE-2018-1000667Improper Restriction of Operations within the Bounds of a Memory Buffer in Nasm

Severity
5.5MEDIUMNVD
EPSS
0.2%
top 57.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 6
Latest updateMay 13

Description

NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory corruption (crashed) of nasm when handling a crafted file due to function assemble_file(inname, depend_ptr) at asm/nasm.c:482. vulnerability in function assemble_file(inname, depend_ptr) at asm/nasm.c:482. that can result in aborting/crash nasm program. This attack appear to be exploitable via a specially crafted asm file..

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/nasm< nasm 2.14-1 (bookworm)
Debiannasm/nasm< 2.14-1+3

🔴Vulnerability Details

2
GHSA
GHSA-mx2f-ggfx-v955: NASM nasm-22022-05-13
OSV
CVE-2018-1000667: NASM nasm-22018-09-06

📋Vendor Advisories

2
Red Hat
nasm: Memory corruption in assemble_file() function in asm/nasm.c:4822018-09-06
Debian
CVE-2018-1000667: nasm - NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory ...2018

💬Community

2
Bugzilla
CVE-2018-1000667 nasm: Memory corruption in assemble_file() function in asm/nasm.c:482 [fedora-all]2018-09-06
Bugzilla
CVE-2018-1000667 nasm: Memory corruption in assemble_file() function in asm/nasm.c:4822018-09-06