PT-2004-1043 · Debian+2 · Debian+2
CVE-2004-1287
·
Publicado
2004-12-22
·
Atualizado
2023-12-22
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
nasm version 0.98.38
nasm version 1.2
Debian GNU/Linux nasm (affected versions not specified)
Description
The issue is related to a buffer overflow in the error function in preproc.c for nasm, which allows attackers to execute arbitrary code via a crafted asm file. Multiple vulnerabilities in the nasm package of the Debian GNU/Linux operating system can lead to violations of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations
For nasm version 0.98.38, update to a version that fixes the buffer overflow issue in preproc.c.
For nasm version 1.2, apply the necessary patches or updates to address the buffer overflow vulnerability.
For Debian GNU/Linux nasm, apply the available security updates for the nasm package to mitigate the multiple vulnerabilities.
Exploit
Correção
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Debian
Red Hat
Nasm