Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-8343

Опубликовано: 14 фев. 2019
Источник: redhat
CVSS3: 7.3

Описание

In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in paste_tokens in asm/preproc.c.

Отчет

This issue affects the versions of nasm as shipped with Red Hat Enterprise Linux 6 and 7. Red Hat Enterprise Linux 6 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. This has been rated as having a security impact of Low, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/. This issue did not affect the versions of nasm as shipped with Red Hat Enterprise Linux 5.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5nasmNot affected
Red Hat Enterprise Linux 6nasmWill not fix
Red Hat Enterprise Linux 7nasmFix deferred
Red Hat Enterprise Linux 8nasmWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1677636nasm: use-after-free in paste_tokens in asm/preproc.c

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 7 лет назад

In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in paste_tokens in asm/preproc.c.

CVSS3: 7.8
nvd
почти 7 лет назад

In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in paste_tokens in asm/preproc.c.

CVSS3: 7.8
debian
почти 7 лет назад

In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in past ...

CVSS3: 7.8
github
больше 3 лет назад

In Netwide Assembler (NASM) 2.14.02, there is a use-after-free in paste_tokens in asm/preproc.c.

7.3 High

CVSS3