Name
nasm
Version
2.15.05
Type
library
Description
General-purpose x86 assembler
Licenses
BSD-2-Clause
PURL
-
CPE
cpe:2.3:*:*:netwide_assembler:2.15.05:*:*:*:*:*:*:*
Other Versions#
Patches#
#
Title
Author
Resolve
1
stdlib: Add strlcat
Joshua Watt <JPEWhacker@gmail.com>
2
BR3392637: output/outieee: Fix nil dereference
Cyrill Gorcunov <gorcunov@gmail.com>
CVE-2020-21528
3
quote_for_pmake: fix counter underrun resulting in segfault
"H. Peter Anvin" <hpa@zytor.com>
CVE-2022-4437
4
outieee: fix segfault on empty input
"H. Peter Anvin" <hpa@zytor.com>
CVE-2022-46457
5
Add --debug-prefix-map option
Joshua Watt <JPEWhacker@gmail.com>
Vulnerabilities#
Name
Analysis
Description
Patched
NASM v2.16 was discovered to contain a segmentation violation in the component ieee_write_file at /output/outieee.c.
Exploitable
NASM v2.16 was discovered to contain a heap buffer overflow in the component quote_for_pmake() asm/nasm.c:856
Patched
Use after free in Mojo IPC in Google Chrome prior to 108.0.5359.124 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Patched
A Segmentation Fault issue discovered in in ieee_segment function in outieee.c in nasm 2.14.03 and 2.15 allows remote attackers to cause a denial of service via crafted assembly file.
Exploitable
Buffer Overflow in Netwide Assembler (NASM) v2.15.xx allows attackers to cause a denial of service via 'crc64i' in the component 'nasmlib/crc64'. This issue is different than CVE-2019-7147.