Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-31722: 3392857 – Heap-Buffer-Overflow in NASM( asm/preproc.c:6863 in expand_mmacro)

There exists a heap buffer overflow in nasm 2.16.02rc1 (GitHub commit: b952891).

CVE
#mac#linux#git#buffer_overflow

Self-registration is disabled due to spam issue (mail [email protected] or [email protected] to create an account)

Bug 3392857 - Heap-Buffer-Overflow in NASM( asm/preproc.c:6863 in expand_mmacro)

Summary: Heap-Buffer-Overflow in NASM( asm/preproc.c:6863 in expand_mmacro)

Status:

OPEN

Alias:

None

Product:

NASM

Classification:

Unclassified

Component:

Assembler (show other bugs)

Version:

2.16.xx

Hardware:

All Linux

Importance:

Medium normal

Assignee:

nobody

URL:

Depends on:

Blocks:

Reported:

2023-04-10 23:10 PDT by Daisy Chen

Modified:

2023-04-11 03:51 PDT (History)

CC List:

5 users (show)

Obtained from:

Build from source archive using configure

Attachments

poc file to reproduce the problem (1.57 KB, text/plain)
2023-04-10 23:10 PDT, Daisy Chen

Details

a new poc file that can run nasm without asan and we can analyze it with GDB (2.92 KB, text/plain)
2023-04-11 03:51 PDT, Daisy Chen

Details

Add an attachment (proposed patch, testcase, etc.)

Note You need to log in before you can comment on or make changes to this bug.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907