Medium severity5.5NVD Advisory· Published Sep 6, 2018· Updated Jun 17, 2026
CVE-2018-1000667
CVE-2018-1000667
Description
NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory corruption (crashed) of nasm when handling a crafted file due to function assemble_file(inname, depend_ptr) at asm/nasm.c:482. vulnerability in function assemble_file(inname, depend_ptr) at asm/nasm.c:482. that can result in aborting/crash nasm program. This attack appear to be exploitable via a specially crafted asm file..
Affected products
5- osv-coords4 versionspkg:rpm/opensuse/nasm&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/nasm&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/nasm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP1pkg:rpm/suse/nasm&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2
< 2.14.02-lp151.3.3.1+ 3 more
- (no CPE)range: < 2.14.02-lp151.3.3.1
- (no CPE)range: < 2.14.02-lp152.4.3.1
- (no CPE)range: < 2.14.02-3.4.1
- (no CPE)range: < 2.14.02-3.4.1
Patches
Vulnerability mechanics
References
4- bugzilla.nasm.us/show_bug.cginvdExploitIssue TrackingThird Party Advisory
- github.com/cyrillos/nasm/issues/3nvdExploitThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-07/msg00015.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2020-07/msg00017.htmlnvd
News mentions
0No linked articles in our index yet.