385
VMScore

CVE-2019-6290

Published: 15/01/2019 Updated: 24/08/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 385
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An infinite recursion issue exists in eval.c in Netwide Assembler (NASM) up to and including 2.14.02. There is a stack exhaustion problem resulting from infinite recursion in the functions expr, rexp, bexpr and cexpr in certain scenarios involving lots of '{' characters. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted asm file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nasm netwide assembler

Vendor Advisories

An infinite recursion issue was discovered in evalc in Netwide Assembler (NASM) through 21402 There is a stack exhaustion problem resulting from infinite recursion in the functions expr, rexp, bexpr and cexpr in certain scenarios involving lots of '{' characters Remote attackers could leverage this vulnerability to cause a denial-of-service vi ...
An infinite recursion issue was discovered in evalc in Netwide Assembler (NASM) through 21402 There is a stack exhaustion problem resulting from infinite recursion in the functions expr, rexp, bexpr and cexpr in certain scenarios involving lots of '{' characters Remote attackers could leverage this vulnerability to cause a denial-of-service vi ...