Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-10254

Опубликовано: 21 апр. 2018
Источник: redhat
CVSS3: 3.3

Описание

Netwide Assembler (NASM) 2.13 has a stack-based buffer over-read in the disasm function of the disasm/disasm.c file. Remote attackers could leverage this vulnerability to cause a denial of service or possibly have unspecified other impact via a crafted ELF file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5nasmOut of support scope
Red Hat Enterprise Linux 6nasmOut of support scope
Red Hat Enterprise Linux 7nasmFix deferred
Red Hat Enterprise Linux 8nasmWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1570495nasm: Stack-based buffer over-read in disasm/disasm.c:disasm() can allow attackers to cause a denial of service

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 8 лет назад

Netwide Assembler (NASM) 2.13 has a stack-based buffer over-read in the disasm function of the disasm/disasm.c file. Remote attackers could leverage this vulnerability to cause a denial of service or possibly have unspecified other impact via a crafted ELF file.

CVSS3: 7.8
nvd
больше 8 лет назад

Netwide Assembler (NASM) 2.13 has a stack-based buffer over-read in the disasm function of the disasm/disasm.c file. Remote attackers could leverage this vulnerability to cause a denial of service or possibly have unspecified other impact via a crafted ELF file.

CVSS3: 7.8
debian
больше 8 лет назад

Netwide Assembler (NASM) 2.13 has a stack-based buffer over-read in th ...

CVSS3: 7.8
github
больше 4 лет назад

Netwide Assembler (NASM) 2.13 has a stack-based buffer over-read in the disasm function of the disasm/disasm.c file. Remote attackers could leverage this vulnerability to cause a denial of service or possibly have unspecified other impact via a crafted ELF file.

suse-cvrf
около 6 лет назад

Security update for nasm

3.3 Low

CVSS3