CVE-2017-10686
nasm - security update
7.8
HIGH
CVSS 3.1
EPSS 2.9%
描述
In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function (called by pp_getline()) - it is used again at multiple positions later that could cause multiple damages. For example, it causes a corrupted double-linked list in detoken(), a double free or corruption in delete_Token(), and an out-of-bounds write in detoken(). It has a high possibility to lead to a remote code execution attack.
如何修補 CVE-2017-10686
要修補 CVE-2017-10686,請將受影響套件升級到下列已修補版本。
- —升級至 2.13.02-0.1 或更新版本
- —升級至 2.10.01-1+deb7u1 或更新版本
CVE-2017-10686 正在被利用嗎?
低 — EPSS 為 2.9%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 2.13.02-0.1
- from 0, < 2.10.01-1+deb7u1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.8 | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |