Debian Yasm vulnerabilities

36 known vulnerabilities affecting debian/yasm.

Total CVEs
36
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2LOW34

Vulnerabilities

Page 1 of 2
CVE-2024-22653LOWCVSS 4.82024
CVE-2024-22653 [MEDIUM] CVE-2024-22653: yasm - yasm commit 9defefae was discovered to contain a NULL pointer dereference via th... yasm commit 9defefae was discovered to contain a NULL pointer dereference via the yasm_section_bcs_append function at section.c. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2023-29579MEDIUMCVSS 5.5fixed in yasm 1.3.0-7 (forky)2023
CVE-2023-29579 [MEDIUM] CVE-2023-29579: yasm - yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the componen... yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the component yasm/yasm+0x43b466 in vsprintf. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1.3.0-7) sid: reso
debian
CVE-2023-31973LOWCVSS 5.52023
CVE-2023-31973 [MEDIUM] CVE-2023-31973: yasm - yasm v1.3.0 was discovered to contain a use after free via the function expand_m... yasm v1.3.0 was discovered to contain a use after free via the function expand_mmac_params at /nasm/nasm-pp.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security policy. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2023-29580LOWCVSS 5.52023
CVE-2023-29580 [MEDIUM] CVE-2023-29580: yasm - yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the ... yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the component yasm_expr_create at /libyasm/expr.c. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2023-37732LOWCVSS 5.52023
CVE-2023-37732 [MEDIUM] CVE-2023-37732: yasm - Yasm v1.3.0.78 was found prone to NULL Pointer Dereference in /libyasm/intnum.c ... Yasm v1.3.0.78 was found prone to NULL Pointer Dereference in /libyasm/intnum.c and /elf/elf.c, which allows the attacker to cause a denial of service via a crafted file. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2023-31975LOWCVSS 3.32023
CVE-2023-31975 [LOW] CVE-2023-31975: yasm - yasm v1.3.0 was discovered to contain a memory leak via the function yasm_intnum... yasm v1.3.0 was discovered to contain a memory leak via the function yasm_intnum_copy at /libyasm/intnum.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security policy. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2023-31724LOWCVSS 7.82023
CVE-2023-31724 [HIGH] CVE-2023-31724: yasm - yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the ... yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the function do_directive at /nasm/nasm-pp.c. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2023-31725LOWCVSS 5.52023
CVE-2023-31725 [MEDIUM] CVE-2023-31725: yasm - yasm 1.3.0.55.g101bc was discovered to contain a heap-use-after-free via the fun... yasm 1.3.0.55.g101bc was discovered to contain a heap-use-after-free via the function expand_mmac_params at yasm/modules/preprocs/nasm/nasm-pp.c. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2023-30402LOWCVSS 5.52023
CVE-2023-30402 [MEDIUM] CVE-2023-30402: yasm - YASM v1.3.0 was discovered to contain a heap overflow via the function handle_do... YASM v1.3.0 was discovered to contain a heap overflow via the function handle_dot_label at /nasm/nasm-token.re. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2023-51258LOWCVSS 5.52023
CVE-2023-51258 [MEDIUM] CVE-2023-51258: yasm - A memory leak issue discovered in YASM v.1.3.0 allows a local attacker to cause ... A memory leak issue discovered in YASM v.1.3.0 allows a local attacker to cause a denial of service via the new_Token function in the modules/preprocs/nasm/nasm-pp:1512. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2023-49558LOWCVSS 5.52023
CVE-2023-49558 [MEDIUM] CVE-2023-49558: yasm - An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of se... An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the modules/preprocs/nasm/nasm-pp.c component. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2023-29583LOWCVSS 5.52023
CVE-2023-29583 [MEDIUM] CVE-2023-29583: yasm - yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function... yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr5 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2023-31972LOWCVSS 5.52023
CVE-2023-31972 [MEDIUM] CVE-2023-31972: yasm - yasm v1.3.0 was discovered to contain a use after free via the function pp_getli... yasm v1.3.0 was discovered to contain a use after free via the function pp_getline at /nasm/nasm-pp.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security policy. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2023-49557LOWCVSS 5.52023
CVE-2023-49557 [MEDIUM] CVE-2023-49557: yasm - An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of se... An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasm/section.c component. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2023-49556LOWCVSS 5.52023
CVE-2023-49556 [MEDIUM] CVE-2023-49556: yasm - Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to... Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_delete_term function in the libyasm/expr.c component. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2023-31974LOWCVSS 5.52023
CVE-2023-31974 [MEDIUM] CVE-2023-31974: yasm - yasm v1.3.0 was discovered to contain a use after free via the function error at... yasm v1.3.0 was discovered to contain a use after free via the function error at /nasm/nasm-pp.c. Note: Multiple third parties dispute this as a bug and not a vulnerability according to the YASM security policy. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2023-29581LOWCVSS 5.52023
CVE-2023-29581 [MEDIUM] CVE-2023-29581: yasm - yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token a... yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE: although a libyasm application could become unavailable if this were exploited, the vendor's position is that there is no security relevance because there is either supposed to be input validation before data reaches libyasm, or a sandbox in which
debian
CVE-2023-49554LOWCVSS 5.52023
CVE-2023-49554 [MEDIUM] CVE-2023-49554: yasm - Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to ... Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_directive function in the modules/preprocs/nasm/nasm-pp.c component. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2023-29582LOWCVSS 5.52023
CVE-2023-29582 [MEDIUM] CVE-2023-29582: yasm - yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function... yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr1 at /nasm/nasm-parse.c. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian
CVE-2023-31723LOWCVSS 5.52023
CVE-2023-31723 [MEDIUM] CVE-2023-31723: yasm - yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the ... yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the function expand_mmac_params at /nasm/nasm-pp.c. Scope: local bookworm: open bullseye: open forky: open sid: open trixie: open
debian