CVE-2018-8881
published 2018-03-20CVE-2018-8881: Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the function tokenize in asm/preproc.c, related to an unterminated string.
PriorityP430high7.3CVSS 3.0
AVLACLPRLUIRSUCHIHAH
EPSS
1.13%
62.7th percentile
Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the function tokenize in asm/preproc.c, related to an unterminated string.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | nasm | < nasm 2.13.02-0.1 (bookworm) | nasm 2.13.02-0.1 (bookworm) |
| nasm | nasm | >= 0 < 2.13.02-0.1 | 2.13.02-0.1 |
| nasm | nasm | >= 0 < 2.13.02-0.1 | 2.13.02-0.1 |
| nasm | nasm | >= 0 < 2.13.02-0.1 | 2.13.02-0.1 |
| nasm | nasm | >= 0 < 2.13.02-0.1 | 2.13.02-0.1 |
| nasm | netwide_assembler | — | — |
CVSS provenance
nvdv3.07.3HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.3HIGH
vendor_debian7.3LOW
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
NASM vulnerabilities
vendor_ubuntu·2018-06-28
CVE-2017-10686 NASM vulnerabilities
Title: NASM vulnerabilities
Summary: NASM could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that NASM incorrectly handled certain source files. If a
user or automated system were tricked into processing a specially crafted
source file, a remote attacker could use these issues to cause NASM to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2018-8881: nasm - Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the fun...
vendor_debian·2018·CVSS 7.3
CVE-2018-8881 [HIGH] CVE-2018-8881: nasm - Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the fun...
Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the function tokenize in asm/preproc.c, related to an unterminated string.
Scope: local
bookworm: resolved (fixed in 2.13.02-0.1)
bullseye: resolved (fixed in 2.13.02-0.1)
forky: resolved (fixed in 2.13.02-0.1)
sid: resolved (fixed in 2.13.02-0.1)
trixie: resolved (fixed in 2.13.02-0.1)
Red Hat
nasm: Heap overflow in function tokenize in asm/preproc.c
vendor_redhat·2017-10-18·CVSS 7.3
CVE-2018-8881 [HIGH] CWE-122 nasm: Heap overflow in function tokenize in asm/preproc.c
nasm: Heap overflow in function tokenize in asm/preproc.c
Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the function tokenize in asm/preproc.c, related to an unterminated string.
Package: nasm (Red Hat Enterprise Linux 5) - Not affected
Package: nasm (Red Hat Enterprise Linux 6) - Fix deferred
Package: nasm (Red Hat Enterprise Linux 7) - Fix deferred
Package: nasm (Red Hat Enterprise Linux 8) - Not affected
GHSA
GHSA-x2vw-jwp7-h598: Netwide Assembler (NASM) 2
ghsa_unreviewed·2022-05-13
CVE-2018-8881 [HIGH] CWE-125 GHSA-x2vw-jwp7-h598: Netwide Assembler (NASM) 2
Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the function tokenize in asm/preproc.c, related to an unterminated string.
OSV
CVE-2018-8881: Netwide Assembler (NASM) 2
osv·2018-03-20·CVSS 7.3
CVE-2018-8881 [HIGH] CVE-2018-8881: Netwide Assembler (NASM) 2
Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the function tokenize in asm/preproc.c, related to an unterminated string.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00017.htmlhttps://bugzilla.nasm.us/show_bug.cgi?id=3392446https://usn.ubuntu.com/3694-1/http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-07/msg00017.htmlhttps://bugzilla.nasm.us/show_bug.cgi?id=3392446https://usn.ubuntu.com/3694-1/
2018-03-20
Published