2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2018-1000667" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2018-09-06T17:29:01.860" ,
2024-11-23 09:11:19 +00:00
"lastModified" : "2024-11-21T03:40:21.930" ,
2023-04-24 12:24:31 +02:00
"vulnStatus" : "Modified" ,
2024-12-08 03:06:42 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory corruption (crashed) of nasm when handling a crafted file due to function assemble_file(inname, depend_ptr) at asm/nasm.c:482. vulnerability in function assemble_file(inname, depend_ptr) at asm/nasm.c:482. that can result in aborting/crash nasm program. This attack appear to be exploitable via a specially crafted asm file.."
} ,
{
"lang" : "es" ,
"value" : "NASM nasm-2.13.03 nasm- 2.14rc15 en su versi\u00f3n 2.14rc15 y anteriores contiene una corrupci\u00f3n de memoria (cerrada inesperadamente) de nasm al manejar un archivo manipulado debido a una vulnerabilidad en la funci\u00f3n assemble_file(inname, depend_ptr) en asm/nasm.c:482 que puede resultar en el cierre inesperado del programa nasm. Este ataque parece ser explotable mediante un archivo asm especialmente manipulado."
}
] ,
"metrics" : {
"cvssMetricV30" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.0" ,
"vectorString" : "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" ,
2024-11-23 09:11:19 +00:00
"baseScore" : 5.5 ,
"baseSeverity" : "MEDIUM" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-11-23 09:11:19 +00:00
"availabilityImpact" : "HIGH"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 3.6
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:M/Au:N/C:N/I:N/A:P" ,
2024-11-23 09:11:19 +00:00
"baseScore" : 4.3 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "NETWORK" ,
"accessComplexity" : "MEDIUM" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-11-23 09:11:19 +00:00
"availabilityImpact" : "PARTIAL"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 8.6 ,
"impactScore" : 2.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : true
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-119"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:nasm:netwide_assembler:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "2.14.0" ,
"matchCriteriaId" : "11A2FD4D-BFBA-40EC-9CDE-42D337DF0041"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:nasm:netwide_assembler:2.14.0:rc1:*:*:*:*:*:*" ,
"matchCriteriaId" : "FEEBD480-549D-444B-989C-E7443E111ED3"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:nasm:netwide_assembler:2.14.0:rc10:*:*:*:*:*:*" ,
"matchCriteriaId" : "94607208-5382-45CB-9E0E-24FB04D200F8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:nasm:netwide_assembler:2.14.0:rc11:*:*:*:*:*:*" ,
"matchCriteriaId" : "F7E3C5C7-09E4-42A1-975F-89919BFD8547"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:nasm:netwide_assembler:2.14.0:rc12:*:*:*:*:*:*" ,
"matchCriteriaId" : "23D65F3D-1F5A-47A8-828C-1473560AF68A"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:nasm:netwide_assembler:2.14.0:rc13:*:*:*:*:*:*" ,
"matchCriteriaId" : "5AA3BBE2-0648-49FF-8321-E90E506ECA03"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:nasm:netwide_assembler:2.14.0:rc14:*:*:*:*:*:*" ,
"matchCriteriaId" : "83439808-E136-4A16-897E-34B8CFC9CCA6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:nasm:netwide_assembler:2.14.0:rc15:*:*:*:*:*:*" ,
"matchCriteriaId" : "744EA8F0-8BA6-40F5-AD44-04F6B40F7392"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:nasm:netwide_assembler:2.14.0:rc2:*:*:*:*:*:*" ,
"matchCriteriaId" : "1597D549-DDBD-4333-A631-97BFBFDFA0AC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:nasm:netwide_assembler:2.14.0:rc3:*:*:*:*:*:*" ,
"matchCriteriaId" : "080A0929-752A-4051-85B8-C9E3AFDEFC0E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:nasm:netwide_assembler:2.14.0:rc4:*:*:*:*:*:*" ,
"matchCriteriaId" : "D30835C7-A156-44D1-9AD2-D41ABCDDFA27"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:nasm:netwide_assembler:2.14.0:rc5:*:*:*:*:*:*" ,
"matchCriteriaId" : "7E540236-A8D6-443C-A268-61928ACC8BD6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:nasm:netwide_assembler:2.14.0:rc6:*:*:*:*:*:*" ,
"matchCriteriaId" : "9F8906E7-EF2A-46D1-A494-5393538069CE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:nasm:netwide_assembler:2.14.0:rc7:*:*:*:*:*:*" ,
"matchCriteriaId" : "CAE1ABD3-9948-4D4B-8776-992721A39207"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:nasm:netwide_assembler:2.14.0:rc8:*:*:*:*:*:*" ,
"matchCriteriaId" : "9846285D-5907-4B59-8425-51D40ED7D0F8"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:nasm:netwide_assembler:2.14.0:rc9:*:*:*:*:*:*" ,
"matchCriteriaId" : "DD088CCE-FD7D-4C31-A141-E7C6ACB7901C"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00015.html" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00017.html" ,
"source" : "cve@mitre.org"
} ,
{
"url" : "https://bugzilla.nasm.us/show_bug.cgi?id=3392507" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Exploit" ,
"Issue Tracking" ,
"Third Party Advisory"
]
} ,
{
"url" : "https://github.com/cyrillos/nasm/issues/3" ,
"source" : "cve@mitre.org" ,
"tags" : [
"Exploit" ,
"Third Party Advisory"
]
2024-11-23 09:11:19 +00:00
} ,
{
"url" : "http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00015.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00017.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://bugzilla.nasm.us/show_bug.cgi?id=3392507" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Exploit" ,
"Issue Tracking" ,
"Third Party Advisory"
]
} ,
{
"url" : "https://github.com/cyrillos/nasm/issues/3" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Exploit" ,
"Third Party Advisory"
]
2023-04-24 12:24:31 +02:00
}
]
}