5.5

CVE-2023-29581

Exploit
yasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE: although a libyasm application could become unavailable if this were exploited, the vendor's position is that there is no security relevance because there is either supposed to be input validation before data reaches libyasm, or a sandbox in which the application runs.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Yasm ProjectYasm Version1.3.0.55.g101bc
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.255
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://bugzilla.redhat.com/show_bug.cgi?id=2186333
https://github.com/yasm/yasm/blob/master/SECURITY.md
https://github.com/yasm/yasm/issues/216
Third Party Advisory
Exploit
Issue Tracking
https://github.com/z1r00/fuzz_vuln/blob/main/yasm/segv/delete_Token/readme.md
Third Party Advisory
Exploit