CVE-2017-10686

NameCVE-2017-10686
DescriptionIn Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function (called by pp_getline()) - it is used again at multiple positions later that could cause multiple damages. For example, it causes a corrupted double-linked list in detoken(), a double free or corruption in delete_Token(), and an out-of-bounds write in detoken(). It has a high possibility to lead to a remote code execution attack.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1041-1
NVD severityhigh (attack range: remote)
Debian Bugs867988

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nasm (PTS)wheezy2.10.01-1vulnerable
wheezy (security)2.10.01-1+deb7u1fixed
jessie2.11.05-1vulnerable
stretch2.12.01-1vulnerable
buster, sid2.13.01-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nasmsource(unstable)(unfixed)high867988
nasmsourcewheezy2.10.01-1+deb7u1highDLA-1041-1

Notes

[stretch] - nasm <no-dsa> (Minor issue)
[jessie] - nasm <no-dsa> (Minor issue)
https://bugzilla.nasm.us/show_bug.cgi?id=3392414

Search for package or bug name: Reporting problems