5.5
CVSSv3

CVE-2017-17820

Published: 21/12/2017 Updated: 02/08/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_list_one_macro in asm/preproc.c that will lead to a remote denial of service attack, related to mishandling of operand-type errors.

Vulnerable Product Search on Vulmon Subscribe to Product

nasm netwide assembler 2.14

canonical ubuntu linux 14.04

Vendor Advisories

NASM could be made to crash or run programs if it opened a specially crafted file ...
In Netwide Assembler (NASM) 214rc0, there is a use-after-free in pp_list_one_macro in asm/preprocc that will lead to a remote denial of service attack, related to mishandling of operand-type errors ...