In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in is_mmacro() in asm/preproc.c that will cause a remote denial of service attack, because of a missing check for the relationship between minimum and maximum parameter counts.
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
Link | Tags |
---|---|
http://repo.or.cz/nasm.git/commit/c9244eaadd05b27637cde06021bac3fa1d920aa3 | patch vendor advisory |
https://usn.ubuntu.com/3694-1/ | third party advisory vendor advisory |
https://bugzilla.nasm.us/show_bug.cgi?id=3392436 | issue tracking exploit vendor advisory |