PT-2004-1043 · Debian+2 · Debian+2

CVE-2004-1287

·

Published

2004-12-22

·

Updated

2023-12-22

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions nasm version 0.98.38 nasm version 1.2 Debian GNU/Linux nasm (affected versions not specified)
Description The issue is related to a buffer overflow in the error function in preproc.c for nasm, which allows attackers to execute arbitrary code via a crafted asm file. Multiple vulnerabilities in the nasm package of the Debian GNU/Linux operating system can lead to violations of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely.
Recommendations For nasm version 0.98.38, update to a version that fixes the buffer overflow issue in preproc.c. For nasm version 1.2, apply the necessary patches or updates to address the buffer overflow vulnerability. For Debian GNU/Linux nasm, apply the available security updates for the nasm package to mitigate the multiple vulnerabilities.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04097
CVE-2004-1287
DSA-623-1
RHSA-2005:381
RHSA-2005_381

Affected Products

Debian
Red Hat
Nasm