Описание
NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response-file buffer is freed before the pointer is used, allowing for data corruption or remote code execution.
A flaw was found in NASM, a Netwide Assembler. This vulnerability, known as a heap use after free, occurs when the program attempts to use memory that has already been released. During response file processing, a pointer to freed memory is retained and later accessed. This can lead to data corruption or unexpected program behavior.
Отчет
This Moderate impact vulnerability in NASM affects Red Hat Enterprise Linux and Fedora. A heap use after free flaw occurs during response file processing, which could lead to data corruption or unexpected program behavior when a specially crafted response file is processed. Exploitation requires the processing of a malicious response file.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | nasm | Fix deferred | ||
| Red Hat Enterprise Linux 6 | nasm | Out of support scope | ||
| Red Hat Enterprise Linux 7 | nasm | Fix deferred | ||
| Red Hat Enterprise Linux 8 | nasm | Fix deferred | ||
| Red Hat Enterprise Linux 9 | nasm | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.8 Medium
CVSS3
Связанные уязвимости
NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response-file buffer is freed before the pointer is used, allowing for data corruption or remote code execution.
NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response-file buffer is freed before the pointer is used, allowing for data corruption or remote code execution.
NASM contains a heap use after free vulnerability in response file (-@ ...
NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global depend_file and later dereferenced, as the response-file buffer is freed before the pointer is used, allowing for data corruption or unexpected behavior.
Уязвимость функции process_respfile файла asm/nasm.c ассемблера Netwide Assembler (NASM), позволяющая нарушителю выполнить произвольный код
EPSS
6.8 Medium
CVSS3