Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2018.0129
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2018-0129)
Resumen:The remote host is missing an update for the 'nasm' package(s) announced via the MGASA-2018-0129 advisory.
Descripción:Summary:
The remote host is missing an update for the 'nasm' package(s) announced via the MGASA-2018-0129 advisory.

Vulnerability Insight:
This update provides nasm 2.13.03 and fixes the following security issues:

In Netwide Assembler (NASM) 2.14rc0, there is a 'SEGV on unknown address'
that will cause a remote denial of service attack, because asm/preproc.c
mishandles macro calls that have the wrong number of arguments.

In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer overflow
that will cause a remote denial of service attack, related to a strcpy in
paste_tokens in asm/preproc.c, a similar issue to CVE-2017-11111.

In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read
in the function detoken() in asm/preproc.c that will cause a remote denial
of service attack.

In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in the
pp_list_one_macro function in asm/preproc.c that will cause a remote denial
of service attack, related to mishandling of line-syntax errors.

In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in
do_directive in asm/preproc.c that will cause a remote denial of service
attack.

In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in
is_mmacro() in asm/preproc.c that will cause a remote denial of service
attack, because of a missing check for the relationship between minimum
and maximum parameter counts.

In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in
pp_getline in asm/preproc.c that will cause a remote denial of service
attack.

In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in
pp_verror in asm/preproc.c that will cause a remote denial of service
attack.

In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read
that will cause a remote denial of service attack, related to a while loop
in paste_tokens in asm/preproc.c.

In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in
the function find_cc() in asm/preproc.c that will cause a remote denial of
service attack, because pointers associated with skip_white_ calls are not
validated.

In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in
pp_list_one_macro in asm/preproc.c that will lead to a remote denial of
service attack, related to mishandling of operand-type errors.

Affected Software/OS:
'nasm' package(s) on Mageia 6.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2017-17810
http://repo.or.cz/nasm.git/commit/59ce1c67b16967c652765e62aa130b7e43f21dd4
https://bugzilla.nasm.us/show_bug.cgi?id=3392431
https://usn.ubuntu.com/3694-1/
Common Vulnerability Exposure (CVE) ID: CVE-2017-17811
https://bugzilla.nasm.us/show_bug.cgi?id=3392432
Common Vulnerability Exposure (CVE) ID: CVE-2017-17812
http://repo.or.cz/nasm.git/commit/9b7ee09abfd426b99aa1ea81d19a3b2818eeabf9
https://bugzilla.nasm.us/show_bug.cgi?id=3392424
Common Vulnerability Exposure (CVE) ID: CVE-2017-17813
https://bugzilla.nasm.us/show_bug.cgi?id=3392429
Common Vulnerability Exposure (CVE) ID: CVE-2017-17814
https://bugzilla.nasm.us/show_bug.cgi?id=3392430
Common Vulnerability Exposure (CVE) ID: CVE-2017-17815
http://repo.or.cz/nasm.git/commit/c9244eaadd05b27637cde06021bac3fa1d920aa3
https://bugzilla.nasm.us/show_bug.cgi?id=3392436
Common Vulnerability Exposure (CVE) ID: CVE-2017-17816
https://bugzilla.nasm.us/show_bug.cgi?id=3392426
Common Vulnerability Exposure (CVE) ID: CVE-2017-17817
https://bugzilla.nasm.us/show_bug.cgi?id=3392427
Common Vulnerability Exposure (CVE) ID: CVE-2017-17818
https://bugzilla.nasm.us/show_bug.cgi?id=3392428
Common Vulnerability Exposure (CVE) ID: CVE-2017-17819
http://repo.or.cz/nasm.git/commit/7524cfd91492e6e3719b959498be584a9ced13af
https://bugzilla.nasm.us/show_bug.cgi?id=3392435
Common Vulnerability Exposure (CVE) ID: CVE-2017-17820
https://bugzilla.nasm.us/show_bug.cgi?id=3392433
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.