In NASM 2.15.04rc3, there is a double-free vulnerability in pp_tokline asm/preproc.c. This is fixed in commit 8806c3ca007b84accac21dd88b900fb03614ceb7.
The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Netwide_assembler | Nasm | 2.15.04-rc3 (including) | 2.15.04-rc3 (including) |
Nasm | Ubuntu | bionic | * |
Nasm | Ubuntu | trusty | * |
Nasm | Ubuntu | xenial | * |