In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function find_cc() in asm/preproc.c that will cause a remote denial of service attack, because pointers associated with skip_white_ calls are not validated.
The product dereferences a pointer that it expects to be valid but is NULL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Netwide_assembler | Nasm | 2.14-rc0 (including) | 2.14-rc0 (including) |
Nasm | Ubuntu | artful | * |
Nasm | Ubuntu | esm-apps/xenial | * |
Nasm | Ubuntu | trusty | * |
Nasm | Ubuntu | upstream | * |
Nasm | Ubuntu | xenial | * |