In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in is_mmacro() in asm/preproc.c that will cause a remote denial of service attack, because of a missing check for the relationship between minimum and maximum parameter counts.
References
Link | Resource |
---|---|
http://repo.or.cz/nasm.git/commit/c9244eaadd05b27637cde06021bac3fa1d920aa3 | Patch Vendor Advisory |
https://bugzilla.nasm.us/show_bug.cgi?id=3392436 | Exploit Issue Tracking Vendor Advisory |
https://usn.ubuntu.com/3694-1/ | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2017-12-21T03:00:00
Updated: 2018-06-29T09:57:01
Reserved: 2017-12-20T00:00:00
Link: CVE-2017-17815
JSON object: View
NVD Information
Status : Analyzed
Published: 2017-12-21T03:29:00.397
Modified: 2019-03-26T15:44:48.753
Link: CVE-2017-17815
JSON object: View
Redhat Information
No data.
CWE