Logo
vulnerabilityCVE-2023-29579
Name
CVE-2023-29579
Source
NVD ( link)Debian ( link)
Description
yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the component yasm/yasm+0x43b466 in vsprintf. Note: This has been disputed by third parties who argue this is a bug and not a security issue because yasm is a standalone program not designed to run untrusted code.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
yasm
Patched

Vulnerability Rating#


5.5
CVSSv31

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.3.0
Not Affected
buildroot
master
1.3.0
Not Affected
yocto
kirkstone
1.3.0+gitX
Patched

Resolved with patches#


yasm (yocto:kirkstone)

#
Title
Author
Resolve
1
Make sure CPU feature parsing use large enough string buffer.
Gyorgy Sarvari <skandigraun@gmail.com>
CVE-2023-29579

yasm (yocto:scarthgap)

#
Title
Author
Resolve
1
Make sure CPU feature parsing use large enough string buffer.
Gyorgy Sarvari <skandigraun@gmail.com>
CVE-2023-29579