CVE-2018-19216Use After Free in Netwide Assembler

CWE-416Use After Free7 documents6 sources
Severity
7.8HIGHNVD
EPSS
0.2%
top 54.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 12
Latest updateMay 13

Description

Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDnasm/netwide_assembler< 2.13.02
debiandebian/nasm< nasm 2.13.02-0.1 (bookworm)
Debiannasm/nasm< 2.13.02-0.1+3

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-w654-8m24-4h3m: Netwide Assembler (NASM) before 22022-05-13
OSV
CVE-2018-19216: Netwide Assembler (NASM) before 22018-11-12

📋Vendor Advisories

2
Red Hat
nasm: use-after-free in detoken at asm/preproc.c2018-08-28
Debian
CVE-2018-19216: nasm - Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/p...2018

💬Community

2
Bugzilla
CVE-2018-19216 nasm: use-after-free in detoken at asm/preproc.c [fedora-all]2018-11-21
Bugzilla
CVE-2018-19216 nasm: use-after-free in detoken at asm/preproc.c2018-11-21