Out-of-Bounds Affecting nasm package, versions [,2.14.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.14% (51st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-NASM-2317925
  • published14 Dec 2021
  • disclosed6 Sept 2018
  • creditUnknown

Introduced: 6 Sep 2018

CVE-2018-1000667  (opens in a new tab)
CWE-119  (opens in a new tab)

How to fix?

Upgrade nasm to version 2.14.0 or higher.

Overview

Affected versions of this package are vulnerable to Out-of-Bounds. NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory corruption (crashed) of nasm when handling a crafted file due to function assemble_file(inname, depend_ptr) at asm/nasm.c:482. vulnerability in function assemble_file(inname, depend_ptr) at asm/nasm.c:482. that can result in aborting/crash nasm program. This attack appear to be exploitable via a specially crafted asm file..

CVSS Scores

version 3.1