CVE-2022-44370Out-of-bounds Write in Netwide Assembler

Severity
7.8HIGHNVD
EPSS
0.1%
top 81.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 29
Latest updateFeb 15

Description

NASM v2.16 was discovered to contain a heap buffer overflow in the component quote_for_pmake() asm/nasm.c:856

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages11 packages

debiandebian/nasm< nasm 2.16.01-1 (bookworm)
Debiannasm/nasm< 2.16.01-1+2

🔴Vulnerability Details

2
GHSA
GHSA-5hm2-2whx-4749: NASM v22023-03-29
OSV
CVE-2022-44370: NASM v22023-03-29

📋Vendor Advisories

4
CISA ICS
Siemens SCALANCE XCM-/XRM-3002024-02-15
Microsoft
NASM v2.16 was discovered to contain a heap buffer overflow in the component quote_for_pmake() asm/nasm.c:8562023-03-14
Red Hat
nasm: heap buffer overflow in quote_for_pmake() in asm/nasm.c2022-10-02
Debian
CVE-2022-44370: nasm - NASM v2.16 was discovered to contain a heap buffer overflow in the component quo...2022
CVE-2022-44370 — Out-of-bounds Write | cvebase