Infinite Loop Vulnerability in nasm Affecting Development Tools
CVE-2021-45257

5.5MEDIUM

Key Information:

Vendor

Nasm

Vendor
CVE Published:
22 December 2021

What is CVE-2021-45257?

An infinite loop vulnerability has been identified in nasm version 2.16rc0, specifically in the gpaste_tokens function. This vulnerability can lead to significant performance degradation by causing the affected application to become unresponsive, potentially impacting development workflows and overall system performance. It is crucial for developers using this version to monitor their applications and implement patches as necessary to mitigate the risk associated with this flaw.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.