Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-29581

Опубликовано: 12 апр. 2023
Источник: debian
EPSS Низкий

Описание

yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE: although a libyasm application could become unavailable if this were exploited, the vendor's position is that there is no security relevance because there is either supposed to be input validation before data reaches libyasm, or a sandbox in which the application runs.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
yasmunfixedpackage

Примечания

  • https://github.com/yasm/yasm/issues/216

  • Crash in CLI tool, no security impact

EPSS

Процентиль: 12%
0.0004
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 3 года назад

yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE: although a libyasm application could become unavailable if this were exploited, the vendor's position is that there is no security relevance because there is either supposed to be input validation before data reaches libyasm, or a sandbox in which the application runs.

CVSS3: 5.5
nvd
почти 3 года назад

yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE: although a libyasm application could become unavailable if this were exploited, the vendor's position is that there is no security relevance because there is either supposed to be input validation before data reaches libyasm, or a sandbox in which the application runs.

CVSS3: 5.5
github
почти 3 года назад

yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the function delete_Token at /nasm/nasm-pp.c.

EPSS

Процентиль: 12%
0.0004
Низкий