Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2005-1194.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://www.redhat.com/support/errata/RHSA-2005-381.html | vendor advisory not applicable |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11299 | signature vdb entry broken link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/18540 | third party advisory vdb entry |
http://tigger.uic.edu/~jlongs2/holes/nasm.txt | vendor advisory exploit |