Memory Access Vulnerability in Netwide Assembler by NASM
CVE-2020-24242

5.5MEDIUM

Key Information:

Vendor

Nasm

Vendor
CVE Published:
25 August 2020

What is CVE-2020-24242?

In Netwide Assembler (NASM) 2.15rc10, a vulnerability exists that allows a segmentation fault (SEGV) to be triggered in the tok_text function within asm/preproc.c. This occurs due to improper handling of READ memory access, potentially leading to instability or unexpected behavior in applications utilizing NASM, which can compromise system security.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.