PT-2004-1043 · Debian+2 · Debian+2

CVE-2004-1287

·

Publicado

2004-12-22

·

Atualizado

2023-12-22

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions nasm version 0.98.38 nasm version 1.2 Debian GNU/Linux nasm (affected versions not specified)
Description The issue is related to a buffer overflow in the error function in preproc.c for nasm, which allows attackers to execute arbitrary code via a crafted asm file. Multiple vulnerabilities in the nasm package of the Debian GNU/Linux operating system can lead to violations of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations For nasm version 0.98.38, update to a version that fixes the buffer overflow issue in preproc.c. For nasm version 1.2, apply the necessary patches or updates to address the buffer overflow vulnerability. For Debian GNU/Linux nasm, apply the available security updates for the nasm package to mitigate the multiple vulnerabilities.

Exploit

Correção

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04097
CVE-2004-1287
DSA-623-1
RHSA-2005:381
RHSA-2005_381

Produtos afetados

Debian
Red Hat
Nasm