CVE Vulnerabilities

CVE-2023-29581

Published: Apr 12, 2023 | Modified: Aug 02, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
LOW

yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE: although a libyasm application could become unavailable if this were exploited, the vendors position is that there is no security relevance because there is either supposed to be input validation before data reaches libyasm, or a sandbox in which the application runs.

Affected Software

Name Vendor Start Version End Version
Yasm Yasm_project 1.3.0.55.g101bc (including) 1.3.0.55.g101bc (including)
Yasm Ubuntu bionic *
Yasm Ubuntu kinetic *
Yasm Ubuntu lunar *
Yasm Ubuntu mantic *
Yasm Ubuntu trusty *
Yasm Ubuntu xenial *

References