Buffer Overflow Vulnerability in NASM by The NASM Project
CVE-2022-29654

5.5MEDIUM

Key Information:

Vendor

Nasm

Vendor
CVE Published:
22 August 2023

What is CVE-2022-29654?

A buffer overflow vulnerability exists in the 'quote_for_pmake' function of the NASM (Netwide Assembler) software prior to version 2.15.05. This flaw can be exploited by attackers through specially crafted files, potentially leading to a denial of service condition. The vulnerability stems from improper handling of input, allowing an attacker to corrupt memory and disrupt normal operations, underscoring the importance of upgrading to secure versions.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.